wifi: mwifiex: fix permanently busy scans after multiple roam iterations
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix permanently busy scans after multiple roam iterations In order for the firmware to sleep, the driver has to confirm a previously received sleep request. The normal sequence of evets goes like this: EVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm -> SLEEP -> EVENT_AWAKE -> AWAKE. Before sending the sleep-confirm command, the driver must make sure there are no commands either running or waiting to be completed. mwifiex_ret_802_11_associate() unconditionally sets ps_state = PS_STATE_AWAKE when it processes the association command response, outside of the normal powersave management flow. If EVENT_SLEEP arrives while the association command is in flight, ps_state is PRE_SLEEP when the association command response is parsed, and the forced AWAKE overwrites it. The deferred sleep-confirm is never sent. A subsequent scan_start command is correctly acknowledged, but the firmware doesn't generate scan_result events. The scan request never finishes, and additional requests from userspace fail with -EBUSY. After testing on both IW412 and W8997, I could only trigger the bug on the IW412 and observed the firmwares behave differently. On the IW412 the firmware still sends EVENT_SLEEP while the authentication / association process is ongoing. A W8997 under the same conditions seems to suppress power-save for the duration of the association, so PRE_SLEEP never coincided with the association response even after extended periods of testing using the loops described below (>12hours). On the IW412, the delay between commands that triggers an EVENT_SLEEP was empirically determined to be ~20ms. This delay can naturally occur when the driver is outputting debugging information (debug_mask = 0x00000037), in which situation the busy scans issue is repeatable while running "test 1)" as described below. If the delay between commands is less than ~20ms, the firmware stays awake and the issue was not reproducible running the same test. The host_mlme=false path also behaves differently. In this case, the entire authentication / association transaction is executed by one command (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit EVENT_SLEEP while the command is running. Remove the assignment so the ps_state is only manipulated in the paths that are related to powersave event handling and on the main workqueue for correct sleep confirmation. The following loop tests were performed (with debugging output enabled): 1) force roaming between two AP's, one 5GHz and one 2.4GHz, same SSID. Use wpa_cli to trigger the roaming behavior, sleep 2s between iterations. 2) force a disconnection to AP 1 and a connection to AP 2, test scan. Use wpa_cli to trigger the connection changes, sleep 2s between iterations. Each test ran in each device for at least 3 hours.
- Yayın
- 15 Ağu 2026
- Güncelleme
- 17 Ağu 2026
- EPSS
- %0,3 · 16. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
0
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,3
Etkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 3.0etkilenir
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · 2ed36b2586f16c480ed58de303af704c2235e16d öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · 5796eabe435d83544b6fe39851ce47ca68fdb778 öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · 31a2c409f8f58d20f0f6391c151421155768ed77 öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · deb5f0ae384f1cf41fccaf6375266db2f2911b2b öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · 1bc55db2d34756bd53e4460dbb699619ee13cd7f öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · a59cfa165aee3e29d06145041c0ebe46a51de604 öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · 6126e12bf8c87badeab41a164c9689ac88e5c160 öncesietkilenir · git
- 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ve sonrası · d78a407bad6f500884a8606aea1a5a9207be4030 öncesietkilenir · git
- 3.0 öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.180-1 öncesi | 6.1.180-1 |
| Debian:13 | linux | 6.12.100-1 öncesi | 6.12.100-1 |
| Debian:14 | linux | 7.1.5-1 öncesi | 7.1.5-1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Planlayın
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Planlayın
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Planlayın
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Planlayın
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Planlayın
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 1bc55db2d34756bd53e4460dbb699619ee13cd7f | Üretici (CNA) |
| Linux Linux | 2ed36b2586f16c480ed58de303af704c2235e16d | Üretici (CNA) |
| Linux Linux | 31a2c409f8f58d20f0f6391c151421155768ed77 | Üretici (CNA) |
| Linux Linux | 5796eabe435d83544b6fe39851ce47ca68fdb778 | Üretici (CNA) |
| Linux Linux | 6126e12bf8c87badeab41a164c9689ac88e5c160 | Üretici (CNA) |
| Linux Linux | a59cfa165aee3e29d06145041c0ebe46a51de604 | Üretici (CNA) |
| Linux Linux | d78a407bad6f500884a8606aea1a5a9207be4030 | Üretici (CNA) |
| Linux Linux | deb5f0ae384f1cf41fccaf6375266db2f2911b2b | Üretici (CNA) |
| debian:linux | 6.1.180-1 · Debian:12 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.
Zayıflık sınıfı (CWE)
—
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f
- git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d
- git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77
- git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778
- git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160
- git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604
- git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030
- git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.