← All Advisories

Linux Kernel mac80211 IBSS Leave Path Flushes Stations and Turns Off the Carrier Without Waiting for In-Flight TX to Complete, Leading to Use-After-Free on Concurrent Packet Transmission

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-93804

Key Details

CVECVE-2026-93804

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: ibss: wait for in-flight TX on disconnect

While leaving an IBSS in ieee80211_ibss_disconnect() mac80211 flushes

stations, turns the carrier off and immediately tells the driver to

leave as well. While there may be synchronize_net() in station flush

and in this code later, packets can still be transmitted due to

cross-CPU race conditions after carrier off is set.

Therefore, it's possible for a race to happen where a TX to the

driver occurs while or after telling it to leave the IBSS. This can

be confusing to drivers, and in the case of iwlwifi leads to an

attempt to use invalid queues.

Move netif_carrier_off() to occur before sta_info_flush() during

IBSS disconnect, and add synchronize_net() if flushing didn't,

so that the synchronize_net() always happens between turning the

carrier off and telling the driver, avoiding this race. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93804
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93804