Home

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->links_map When an arvif is initialized in non-AP STA mode but MLO connection preparation fails before the arvif is created (arvif->is_created remains false), the error path attempts to delete all links. However, link deletion only executes when arvif->is_created is true. As a result, ahvif retains a stale entry of arvif that is initialized but not created. When a new arvif is initialized with the same link id, this stale mapping triggers the following WARN_ON. WARNING: drivers/net/wireless/ath/ath12k/mac.c:4271 at ath12k_mac_op_change_vif_links+0x140/0x180 [ath12k], CPU#3: wpa_supplicant/275 Call trace: ath12k_mac_op_change_vif_links+0x140/0x180 [ath12k] (P) drv_change_vif_links+0xbc/0x1a4 [mac80211] ieee80211_vif_update_links+0x54c/0x6a0 [mac80211] ieee80211_vif_set_links+0x40/0x70 [mac80211] ieee80211_prep_connection+0x84/0x450 [mac80211] ieee80211_mgd_auth+0x200/0x480 [mac80211] ieee80211_auth+0x14/0x20 [mac80211] cfg80211_mlme_auth+0x90/0xf0 [cfg80211] nl80211_authenticate+0x32c/0x380 [cfg80211] genl_family_rcv_msg_doit+0xc8/0x134 Fix this issue by unassigning the link vif and clearing ahvif->links_map if arvif is only initialized but not created. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.5-01651-QCAHKSWPL_SILICONZ-1

PUBLISHED Reserved 2026-05-13 | Published 2026-06-03 | Updated 2026-06-03 | Assigner Linux

Product status

Default status
unaffected

81e4be30544ee7e8da80e9aae7acd69d3be6d05a (git) before da289440f04c93048d82d293b180f1cacdfee2d9
affected

81e4be30544ee7e8da80e9aae7acd69d3be6d05a (git) before acd8319e834be6790e449701cb6df0f636801977
affected

81e4be30544ee7e8da80e9aae7acd69d3be6d05a (git) before 2c1ba9c2adf0fda96eaaebd8799268a7506a8fc9
affected

Default status
affected

6.15
affected

Any version before 6.15
unaffected

6.18.14 (semver)
unaffected

6.19.4 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/da289440f04c93048d82d293b180f1cacdfee2d9

git.kernel.org/...c/acd8319e834be6790e449701cb6df0f636801977

git.kernel.org/...c/2c1ba9c2adf0fda96eaaebd8799268a7506a8fc9

cve.org (CVE-2026-46248)

nvd.nist.gov (CVE-2026-46248)

Download JSON