Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm Wi-Fi driver (ath11k) that could lead to a system crash. When the Wi-Fi hardware fails to initialize properly, the system may attempt to release the same memory twice during cleanup. This issue primarily affects virtual machine environments or systems with specific hardware initialization failures, potentially causing a denial-of-service (system crash).
Technical details
A double-free vulnerability exists in the ath11k driver within the Linux kernel's networking subsystem. The root cause is located in the 'ath11k_dp_free' function in 'drivers/net/wireless/ath/ath11k/dp.c', where 'dp->tx_ring[i].tx_status' buffers are released during firmware initialization errors and subsequently released again during device unbinding (ath11k_pci_remove). An attacker or a system failure (such as MSI addressing failure in a VM) can trigger this condition, leading to a kernel panic or memory corruption. The fix involves setting the buffer pointer to NULL immediately after the first free to prevent the subsequent deallocation attempt. Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux 5.6 through 5.10.260, 5.15.162, 6.1.97, 6.6.37, 6.9.8
Timeline
- 2026-04-20: disclosed: Patch submitted by Jose Ignacio Tornos Martinez
- 2026-07-04: patched: Commits merged into stable trees by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-63822 published
References
- https://git.kernel.org/stable/c/051f954b94479d72222c9fbc82a3eef4777bca01
- https://git.kernel.org/stable/c/0a946abb82f29abe9a15173b707a449cb039b43e
- https://git.kernel.org/stable/c/0aa097a370277deab5337030b9e2d395742f469c
- https://git.kernel.org/stable/c/318703b6f71d1a29ee0ac46c32a38f7734d4cfb2
- https://git.kernel.org/stable/c/40aa3c2b0cb8e34e0576fc94cc70e4e33db03c0a
- https://git.kernel.org/stable/c/7b2e62b9080bf4a5f4e70cfe47156df8d93a4f13
- https://git.kernel.org/stable/c/8b7a26b6681922a38cd5a7829ace61f8e54df9b7