In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
ath12kmacvdev_create() has three error path issues that leave arvif in an inconsistent state:
When ath12kwmivdev_create() fails, the function returns directly without clearing arvif->ar, which was already set before the WMI call. Subsequent code checking arvif->ar to determine vdev readiness will see a non-NULL value despite no vdev existing in firmware.
When ath12kwmisendpeerdeletecmd() fails in errpeerdel, the code jumped to err: skipping the DP peer cleanup and vdev rollback, leaving numcreated_vdevs, vdev maps and arvif list membership live.
When ath12kwaitforpeerdeletedone() fails, the code jumped to errvdev_del: skipping the DP peer cleanup.
Fix by changing the ath12kwmivdevcreate() failure to goto err instead of returning directly, routing both errpeerdel failure paths through errdppeerdel: for proper DP peer and vdev rollback, and consolidating the arvif state cleanup at err:.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPLV1.0V2.0_SILICONZ-1.115823.3
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74367.json"
}