Junglewise Threat Intelligence

CVE-2026-80939: Linux kernel rtw89 PCI driver missing shutdown handler

CVE-2026-80939 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's rtw89 Wi-Fi driver lacked a shutdown handler, causing it to continue polling the wireless hardware during system reboot. On ARM64 platforms, this led to system panics when the PCIe link was torn down while the driver was still attempting to read from the disconnected device. The fix adds a shutdown callback to gracefully stop polling before the hardware is no longer accessible.

Technical details

This vulnerability is a missing shutdown callback in the rtw89 PCI driver. During system reboot, the kernel calls device_shutdown() on all drivers, but the rtw89 driver had no .shutdown callback to stop its rfkill polling work. After the PCIe link is torn down, the polling handler issues MMIO reads to an unresponsive device, triggering a fatal asynchronous SError exception on ARM64 platforms. The fix adds rtw89_pci_shutdown() which sets an RTW89_FLAG_SHUTDOWN flag to make rfkill_poll() return early, preventing MMIO access after shutdown begins. No authentication or user interaction is required; the panic occurs automatically during reboot on affected arm64 systems.

Affected products

  • Linux Linux kernel versions with rtw89 driver and hardware rfkill polling

Timeline

  • 2026-09-11: disclosed

Related threats