CVE-2026-46069
published 2026-05-27CVE-2026-46069: In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() The…
high7
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
The mwifiex_adapter_cleanup() function uses timer_delete()
(non-synchronous) for the wakeup_timer before the adapter structure is
freed. This is incorrect because timer_delete() does not wait for any
running timer callback to complete.
If the wakeup_timer callback (wakeup_timer_fn) is executing when
mwifiex_adapter_cleanup() is called, the callback will continue to
access adapter fields (adapter->hw_status, adapter->if_ops.card_reset,
etc.) which may be freed by mwifiex_free_adapter() called later in the
mwifiex_remove_card() path.
Use timer_delete_sync() instead to ensure any running timer callback has
completed before returning.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 4636187da60b6e33526050235c610409d9cc00e8 < 11869ce402d95519d49b25a2a97741f68d69d103 | 11869ce402d95519d49b25a2a97741f68d69d103 |
| linux | linux | >= 4636187da60b6e33526050235c610409d9cc00e8 < 63fe3389b3e092d6c0eeea9fc0318e7918b16618 | 63fe3389b3e092d6c0eeea9fc0318e7918b16618 |
| linux | linux | >= 4636187da60b6e33526050235c610409d9cc00e8 < 4e179a60a60c0a5aea245e8e67768343c0f070b8 | 4e179a60a60c0a5aea245e8e67768343c0f070b8 |
| linux | linux | >= 4636187da60b6e33526050235c610409d9cc00e8 < 030abbae49cf9fd1fba7aa08e15ec81efbeb78cf | 030abbae49cf9fd1fba7aa08e15ec81efbeb78cf |
| linux | linux | >= 4636187da60b6e33526050235c610409d9cc00e8 < ae5e95d4157481693be2317e3ffcd84e36010cbb | ae5e95d4157481693be2317e3ffcd84e36010cbb |
| linux | linux_kernel | — | — |