In the Linux kernel, the following vulnerability has been resolved:
ath11k: fix kernel panic during unload/load ath11k modules
Call netifnapidel() from ath11kahbfreeextirq() to fix the following kernel panic when unload/load ath11k modules for few iterations.
[ 971.201365] Unable to handle kernel paging request at virtual address 6d97a208 [ 971.204227] pgd = 594c2919 [ 971.211478] [6d97a208] *pgd=00000000 [ 971.214120] Internal error: Oops: 5 [#1] PREEMPT SMP ARM [ 971.412024] CPU: 2 PID: 4435 Comm: insmod Not tainted 5.4.89 #0 [ 971.434256] Hardware name: Generic DT based system [ 971.440165] PC is at napibyid+0x10/0x40 [ 971.445019] LR is at netifnapiadd+0x160/0x1dc
[ 971.743127] (napibyid) from [<807d89a0>] (netifnapiadd+0x160/0x1dc) [ 971.751295] (netifnapiadd) from [<7f1209ac>] (ath11kahbconfigirq+0xf8/0x414 [ath11kahb]) [ 971.759164] (ath11kahbconfigirq [ath11kahb]) from [<7f12135c>] (ath11kahbprobe+0x40c/0x51c [ath11kahb]) [ 971.768567] (ath11kahbprobe [ath11kahb]) from [<80666864>] (platformdrvprobe+0x48/0x94) [ 971.779670] (platformdrvprobe) from [<80664718>] (reallyprobe+0x1c8/0x450) [ 971.789389] (reallyprobe) from [<80664cc4>] (driverprobedevice+0x15c/0x1b8) [ 971.797547] (driverprobedevice) from [<80664f60>] (devicedriverattach+0x44/0x60) [ 971.805795] (devicedriverattach) from [<806650a0>] (driverattach+0x124/0x140) [ 971.814822] (driverattach) from [<80662adc>] (busforeachdev+0x58/0xa4) [ 971.823328] (busforeachdev) from [<80663a2c>] (busadddriver+0xf0/0x1e8) [ 971.831662] (busadddriver) from [<806658a4>] (driverregister+0xa8/0xf0) [ 971.839822] (driverregister) from [<8030269c>] (dooneinitcall+0x78/0x1ac) [ 971.847638] (dooneinitcall) from [<80392524>] (doinitmodule+0x54/0x200) [ 971.855968] (doinitmodule) from [<803945b0>] (loadmodule+0x1e30/0x1ffc) [ 971.864126] (loadmodule) from [<803948b0>] (sysinitmodule+0x134/0x17c) [ 971.871852] (sysinitmodule) from [<80301000>] (retfastsyscall+0x0/0x50)
Tested-on: IPQ8074 hw2.0 AHB WLAN.HK.2.6.0.1-00760-QCAHKSWPL_SILICONZ-1
[ { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c4b7653af62a9a5efe2856183d1f987c5429758b", "target": { "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "line_hashes": [ "258372981717493590377249280499373627426", "38589637071097538064362282248768220231", "191516342886786114840886306357939449063", "121502595523639521626828435591607007251" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2022-49131-15cf3732", "signature_version": "v1", "signature_type": "Line" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@699e8c87e5c406af0f0606f40eeebd248c51b702", "target": { "function": "ath11k_ahb_free_ext_irq", "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "function_hash": "110298175546667422865084429345330707671", "length": 282.0 }, "deprecated": false, "id": "CVE-2022-49131-4ac60f0e", "signature_version": "v1", "signature_type": "Function" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22b59cb965f79ee1accf83172441c9ca0ecb632a", "target": { "function": "ath11k_ahb_free_ext_irq", "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "function_hash": "110298175546667422865084429345330707671", "length": 282.0 }, "deprecated": false, "id": "CVE-2022-49131-6d907db9", "signature_version": "v1", "signature_type": "Function" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6a815f5abdf324108799829dd19ea62fef4bf95", "target": { "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "line_hashes": [ "258372981717493590377249280499373627426", "38589637071097538064362282248768220231", "191516342886786114840886306357939449063", "121502595523639521626828435591607007251" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2022-49131-723ead68", "signature_version": "v1", "signature_type": "Line" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38e488db194dc16d2eb23c77c6a8c04ff583c40d", "target": { "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "line_hashes": [ "258372981717493590377249280499373627426", "38589637071097538064362282248768220231", "191516342886786114840886306357939449063", "121502595523639521626828435591607007251" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2022-49131-73ecca81", "signature_version": "v1", "signature_type": "Line" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22b59cb965f79ee1accf83172441c9ca0ecb632a", "target": { "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "line_hashes": [ "258372981717493590377249280499373627426", "38589637071097538064362282248768220231", "191516342886786114840886306357939449063", "121502595523639521626828435591607007251" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2022-49131-96bafbf2", "signature_version": "v1", "signature_type": "Line" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c4b7653af62a9a5efe2856183d1f987c5429758b", "target": { "function": "ath11k_ahb_free_ext_irq", "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "function_hash": "110298175546667422865084429345330707671", "length": 282.0 }, "deprecated": false, "id": "CVE-2022-49131-9bd9b06c", "signature_version": "v1", "signature_type": "Function" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6a815f5abdf324108799829dd19ea62fef4bf95", "target": { "function": "ath11k_ahb_free_ext_irq", "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "function_hash": "110298175546667422865084429345330707671", "length": 282.0 }, "deprecated": false, "id": "CVE-2022-49131-b303015a", "signature_version": "v1", "signature_type": "Function" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@38e488db194dc16d2eb23c77c6a8c04ff583c40d", "target": { "function": "ath11k_ahb_free_ext_irq", "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "function_hash": "110298175546667422865084429345330707671", "length": 282.0 }, "deprecated": false, "id": "CVE-2022-49131-ce40d667", "signature_version": "v1", "signature_type": "Function" }, { "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@699e8c87e5c406af0f0606f40eeebd248c51b702", "target": { "file": "drivers/net/wireless/ath/ath11k/ahb.c" }, "digest": { "line_hashes": [ "258372981717493590377249280499373627426", "38589637071097538064362282248768220231", "191516342886786114840886306357939449063", "121502595523639521626828435591607007251" ], "threshold": 0.9 }, "deprecated": false, "id": "CVE-2022-49131-e89da193", "signature_version": "v1", "signature_type": "Line" } ]