← All Advisories

CVE-2026-74407

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74407

Key Details

CVECVE-2026-74407
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: cancel SSR work items during PCI shutdown

A reboot can crash the kernel if it overlaps with WLAN firmware crash

recovery (SSR). The crash is a NULL pointer dereference in the MHI teardown

path while freeing DMA-backed MHI contexts.

Simplified trace:

dma_free_attrs

mhi_deinit_dev_ctxt [mhi]

ath11k_pci_power_down [ath11k_pci]

ath11k_pci_shutdown [ath11k_pci]

device_shutdown

kernel_restart

On the host side, SSR is driven by the MHI RDDM callback, which queues

reset_work to perform device recovery. reset_work power-cycles the device

by calling ath11k_hif_power_down() followed by ath11k_hif_power_up(). The

power-down phase deinitializes MHI and frees DMA resources.

Shutdown/reboot runs fully asynchronously with this RDDM-driven SSR

recovery flow. As a result, the shutdown path

(ath11k_pci_shutdown() -> ath11k_pci_power_down()) can race with the SSR

recovery sequence.

Fix this by canceling SSR-related work items during PCI shutdown, marking

the device as unregistering, and serializing the RDDM callback path that

checks and queues reset_work. This ensures that no new SSR recovery work

can be queued once teardown has started, and that any in-flight recovery

work is fully synchronized before device power-down, preventing MHI

teardown and DMA resource freeing from running more than once.

Note: This issue only affects PCI/MHI-based devices. AHB-based ath11k

devices do not queue reset_work in normal SSR flows.

Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74407
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74407