wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
Published Sep 7, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is required to be atomic, however ath11k_mac_disable_peer_fixed_rate() does not follow it as it might sleep. Consequently below warning is seen:
BUG: sleeping function called from invalid context at wmi.c:304 Call Trace: <TASK> dump_stack_lvl __might_resched.cold ath11k_wmi_cmd_send ath11k_wmi_set_peer_param ath11k_mac_disable_peer_fixed_rate ieee80211_iterate_stations_atomic ath11k_mac_op_set_bitrate_mask.cold
Change to ieee80211_iterate_stations_mtx() to fix this issue.
Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.6StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.6
- Version 6.12.42StatusunaffectedConstraints<=6.12.*
- Version 6.15.10StatusunaffectedConstraints<=6.15.*
- Version 6.16.1StatusunaffectedConstraints<=6.16.*
- Version 6.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.6 · < 6.12.42
- ≥ 6.13 · < 6.15.10
- ≥ 6.16 · < 6.16.1
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw in ath11k allowed a sleeping operation to run in an atomic context when setting a bitrate mask, triggering “sleeping function called from invalid context” and potentially leading to a kernel oops or hang. The fix switches to the mutex-based station iterator, aligning the code with the required sleepable context. This results in a local denial of service on systems with ath11k when a privileged user configures bitrate masks.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2025-39732 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2393737 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-31498 Advisory
- https://git.kernel.org/stable/c/65c12b104cb942d588a1a093acc4537fb3d3b129 Patch
- https://git.kernel.org/stable/c/6bdef22d540258ca06f079f7b6ae100669a19b47 Patch
- https://git.kernel.org/stable/c/7d4d0db0dc9424de2bdc0b45e919e4892603356f Patch
- https://git.kernel.org/stable/c/9c0e3144924c7db701575a73af341d33184afeaf Patch
- https://lore.kernel.org/linux-cve-announce/2025090730-CVE-2025-39732-4c7f@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-39732
- https://www.cve.org/CVERecord?id=CVE-2025-39732
Change history (0)
No recorded changes yet.