{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68469","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.396Z","datePublished":"2026-08-15T05:51:27.429Z","dateUpdated":"2026-08-17T05:06:11.253Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:06:11.253Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix permanently busy scans after multiple roam iterations\n\nIn order for the firmware to sleep, the driver has to confirm a\npreviously received sleep request. The normal sequence of evets goes\nlike this:\nEVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm\n-> SLEEP -> EVENT_AWAKE -> AWAKE.\nBefore sending the sleep-confirm command, the driver must make sure\nthere are no commands either running or waiting to be completed.\n\nmwifiex_ret_802_11_associate() unconditionally sets\nps_state = PS_STATE_AWAKE when it processes the association command\nresponse, outside of the normal powersave management flow. If\nEVENT_SLEEP arrives while the association command is in flight,\nps_state is PRE_SLEEP when the association command response is parsed,\nand the forced AWAKE overwrites it. The deferred sleep-confirm is\nnever sent.\n\nA subsequent scan_start command is correctly acknowledged, but the\nfirmware doesn't generate scan_result events. The scan request never\nfinishes, and additional requests from userspace fail with -EBUSY.\n\nAfter testing on both IW412 and W8997, I could only trigger the bug on\nthe IW412 and observed the firmwares behave differently. On the IW412\nthe firmware still sends EVENT_SLEEP while the authentication /\nassociation process is ongoing. A W8997 under the same\nconditions seems to suppress power-save for the duration of the\nassociation, so PRE_SLEEP never coincided with the association response\neven after extended periods of testing using the loops\ndescribed below (>12hours).\n\nOn the IW412, the delay between commands that triggers an EVENT_SLEEP\nwas empirically determined to be ~20ms. This delay can naturally occur\nwhen the driver is outputting debugging information\n(debug_mask = 0x00000037), in which situation the busy scans issue is\nrepeatable while running \"test 1)\" as described below. If the delay\nbetween commands is less than ~20ms, the firmware stays awake and\nthe issue was not reproducible running the same test.\n\nThe host_mlme=false path also behaves differently. In this case, the\nentire authentication / association transaction is executed by one\ncommand (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit\nEVENT_SLEEP while the command is running.\n\nRemove the assignment so the ps_state is only manipulated in the paths\nthat are related to powersave event handling and on the main workqueue\nfor correct sleep confirmation.\n\nThe following loop tests were performed (with debugging output enabled):\n1) force roaming between two AP's, one 5GHz and one 2.4GHz, same\nSSID. Use wpa_cli to trigger the roaming behavior, sleep 2s\nbetween iterations.\n2) force a disconnection to AP 1 and a connection to AP 2, test\nscan. Use wpa_cli to trigger the connection changes, sleep 2s\nbetween iterations.\n\nEach test ran in each device for at least 3 hours."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"versions":[{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"2ed36b2586f16c480ed58de303af704c2235e16d","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"5796eabe435d83544b6fe39851ce47ca68fdb778","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"31a2c409f8f58d20f0f6391c151421155768ed77","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"deb5f0ae384f1cf41fccaf6375266db2f2911b2b","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"1bc55db2d34756bd53e4460dbb699619ee13cd7f","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"a59cfa165aee3e29d06145041c0ebe46a51de604","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"6126e12bf8c87badeab41a164c9689ac88e5c160","status":"affected","versionType":"git"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"d78a407bad6f500884a8606aea1a5a9207be4030","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d"},{"url":"https://git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778"},{"url":"https://git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77"},{"url":"https://git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b"},{"url":"https://git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f"},{"url":"https://git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604"},{"url":"https://git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160"},{"url":"https://git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030"}],"title":"wifi: mwifiex: fix permanently busy scans after multiple roam iterations","x_generator":{"engine":"bippy-1.2.0"}}}}