HIGH Introduced in 3.2
ath6kl AggrTimer UAF
CVE-2026-68198
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy(). If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy(). Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.
02KernelScan AI Analysis
Risk summary
A local user on a system with an ath6kl WiFi adapter can trigger a use-after-free during aggregation timer teardown. The race condition between the timer callback and cleanup path can lead to kernel memory corruption, potentially enabling privilege escalation or denial of service. Exploitation requires specific Atheros AR6003/AR6004 WiFi hardware and winning a timing window.
Vulnerability analysis
The WiFi driver's aggregation cleanup path deletes a timer without waiting for any in-progress callback to finish, then immediately frees the connection state that the callback accesses. If the timer fires concurrently with teardown, the callback dereferences freed memory and can even re-arm itself, widening the race window. The fix replaces the non-synchronous timer deletion with a synchronous one, guaranteeing the callback has fully exited before the caller proceeds to free the structure. This race is reachable locally by any user who can trigger WiFi connection or interface teardown on a system with the affected adapter; the timing-dependent nature of the bug makes exploitation difficult but the memory corruption primitive is unconstrained.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 3.2 | 6.18.42 | 18965470d41e |
| 5.10 | 3.2 | 5.10.266 | a1bac650b2d6 |
| 5.15 | 3.2 | 5.15.217 | 2132a6db0584 |
| 6.1 | 3.2 | 6.1.184 | 17ff29cd8dbc |
| 6.6 | 3.2 | 6.6.151 | 64af6534a085 |
| 7.1 | 3.2 | 7.1.6 | a3313111b5d9 |
| mainline | 3.2 | 7.2 | ba7debb4dd64 |
| 6.12 | 3.2 | 6.12.103 | b5d618fd61b9 |