{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-58096","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-03-06T15:52:09.189Z","datePublished":"2025-04-16T14:11:44.587Z","dateUpdated":"2026-08-05T11:47:42.733Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:47:42.733Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode\n\nath11k_hal_srng_* should be used with srng->lock to protect srng data.\n\nFor ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(),\nthey use ath11k_hal_srng_* for many times but never call srng->lock.\n\nSo when running (full) monitor mode, warning will occur:\nRIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\nCall Trace:\n ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\n ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k]\n ? idr_alloc_u32+0x97/0xd0\n ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]\n ath11k_dp_service_srng+0x289/0x5a0 [ath11k]\n ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k]\n __napi_poll+0x30/0x1f0\n net_rx_action+0x198/0x320\n __do_softirq+0xdd/0x319\n\nSo add srng->lock for them to avoid such warnings.\n\nInorder to fetch the srng->lock, should change srng's definition from\n'void' to 'struct hal_srng'. And initialize them elsewhere to prevent\none line of code from being too long. This is consistent with other ring\nprocess functions, such as ath11k_dp_process_rx().\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The entire code path is driven by 802.11 frames received over the air into the ath11k monitor destination/status rings, so the attacker only needs to be within WiFi radio range of the target. Per kernel scoring guidance, WiFi frame injection is Adjacent.\nAC:L - The attacker controls both sides of the race by injecting frames — high-rate valid traffic drives the monitor status/dest NAPI (ext-IRQ groups 4-6) while malformed/error frames drive ath11k_dp_process_rxdma_err() on the same srng from groups 0-2 — and can widen the window arbitrarily by raising injection rate. The condition also fires spontaneously under normal load, as documented by the sibling fix 16c6c35c03ea reporting repeated invalid buf_id and RCU stalls on WCN6855.\nPR:N - A monitor-mode ath11k radio captures raw frames from any transmitter in range with no association, no 4-way handshake and no credentials of any kind, so the attacker needs zero privileges on the target. The vulnerable ring processing runs entirely pre-authentication on received frames.\nUI:N - Monitor/full-monitor capture is passive and continuous; the reap timer and NAPI poll the rings automatically with no victim action required. The attacker simply transmits frames into the air.\nS:U - The corruption is confined to kernel memory (SRNG descriptors, sk_buff heap objects, DMA mappings) within the same security authority. No VM, IOMMU or sandbox boundary is crossed.\nC:H - Desynchronized ring pointers cause stale/garbage descriptors to be parsed, and the resulting sw_cookie indexes pmon->link_desc_banks[] (size 8) with no bounds check, producing an out-of-array read whose vaddr/paddr are then dereferenced in ath11k_hal_rx_msdu_list_get() — an arbitrary kernel read primitive. The concurrent double-consumption of buf_ids additionally causes freed sk_buff contents to be read back as a hal_rx_desc.\nI:H - Two consumers resolving the same buf_id across non-atomic idr_find()/idr_remove() sections produce a double dma_unmap_single() and double dev_kfree_skb_any() — a double-free/use-after-free of an sk_buff, a well-known heap-corruption write primitive. ath11k_hal_srng_access_end() also publishes a torn tp to the device's shared pointer, letting the hardware DMA into buffers the host still owns.\nA:H - The same-series commit 16c6c35c03ea documents this exact monitor destination ring desynchronization causing an infinite reap loop, RCU stall and kernel crash on WCN6855. The lockdep_assert_held() failures also produce WARNs that panic on panic_on_warn systems, and the UAF/double-free crashes the kernel outright."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"versions":[{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"27ca8004ba93a0665faa6d477eaeb551e03de6c8","status":"affected","versionType":"git"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"1d2178918efc928e11bed9631469ef79ff0a862a","status":"affected","versionType":"git"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"b85758e76b6452740fc2a08ced6759af64c0d59a","status":"affected","versionType":"git"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"63b7af49496d0e32f7a748b6af3361ec138b1bd3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"6.6.123","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.69","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.14.2","lessThanOrEqual":"6.14.*","status":"unaffected","versionType":"semver"},{"version":"6.15","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.123"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.69"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.14.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.15"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/27ca8004ba93a0665faa6d477eaeb551e03de6c8"},{"url":"https://git.kernel.org/stable/c/1d2178918efc928e11bed9631469ef79ff0a862a"},{"url":"https://git.kernel.org/stable/c/b85758e76b6452740fc2a08ced6759af64c0d59a"},{"url":"https://git.kernel.org/stable/c/63b7af49496d0e32f7a748b6af3361ec138b1bd3"}],"title":"wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode","x_generator":{"engine":"bippy-1.2.0"}}}}