ACK: [SRU][J][PATCH 0/1] CVE-2024-58096

Andrei Gherzan andrei.gherzan at canonical.com
Mon Sep 14 23:55:22 UTC 2026


On 26/09/09 05:47PM, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2024-58096
> 
> [ Impact ]
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode
> 
> ath11k_hal_srng_* should be used with srng->lock to protect srng data.
> 
> For ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(), they
> use ath11k_hal_srng_* for many times but never call srng->lock.
> 
> So when running (full) monitor mode, warning will occur: RIP:
> 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] Call Trace: ?
> ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]
> ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k] ? idr_alloc_u32+0x97/0xd0
> ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]
> ath11k_dp_service_srng+0x289/0x5a0 [ath11k]
> ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k] __napi_poll+0x30/0x1f0
> net_rx_action+0x198/0x320 __do_softirq+0xdd/0x319
> 
> So add srng->lock for them to avoid such warnings.
> 
> Inorder to fetch the srng->lock, should change srng's definition from 'void' to
> 'struct hal_srng'. And initialize them elsewhere to prevent one line of code
> from being too long. This is consistent with other ring process functions, such
> as ath11k_dp_process_rx().
> 
> Tested-on: WCN6855 hw2.0 PCI
> WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074
> hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1
> 
> [ Fix ]
> 
> jammy/linux: backported from 63b7af49496d
> 
> The upstream fix touches two functions, ath11k_dp_rx_mon_dest_process() and
> ath11k_dp_full_mon_process_rx(). In the jammy/linux tree only the former
> locking hunk was applied (the srng type change plus the srng->lock/unlock
> pair). The ath11k_dp_full_mon_process_rx() hunk was dropped because full
> monitor mode, including that function and its associated ath11k_mon_data
> members, does not exist in this tree.
> 
> [ Test Plan ]
> 
> Build and boot tested.
> 
> [ Where Problems Could Occur ]
> 
> A bad fix would primarily affect systems using Qualcomm ath11k Wi-Fi devices
> (such as WCN6855 and QCN9074) when the driver is placed in monitor mode, where
> incorrect locking around the srng ring processing could lead to lost packets,
> data races or a deadlock in the receive softirq path. Users without ath11k
> hardware, or who never enable monitor mode, are not affected by this change.
> 
> [ Other Info ]
> 
> Kybele flow-v11-25-ga27c0fa6. Reference: 73fd1ce0/v1

Acked-by: Andrei Gherzan <andrei.gherzan at canonical.com>

-- 
Andrei Gherzan
gpg: rsa4096/D4D94F67AD0E9640
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260915/620ddcdc/attachment.sig>


More information about the kernel-team mailing list