Back

HIGH

wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()

Published Sep 7, 2025

Description

ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is required to be atomic, however ath11k_mac_disable_peer_fixed_rate() does not follow it as it might sleep. Consequently below warning is seen:

BUG: sleeping function called from invalid context at wmi.c:304 Call Trace: <TASK> dump_stack_lvl __might_resched.cold ath11k_wmi_cmd_send ath11k_wmi_set_peer_param ath11k_mac_disable_peer_fixed_rate ieee80211_iterate_stations_atomic ath11k_mac_op_set_bitrate_mask.cold

Change to ieee80211_iterate_stations_mtx() to fix this issue.

Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30

Affected products

Remediation

Red Hat statement

A flaw in ath11k allowed a sleeping operation to run in an atomic context when setting a bitrate mask, triggering “sleeping function called from invalid context” and potentially leading to a kernel oops or hang. The fix switches to the mutex-based station iterator, aligning the code with the required sleepable context. This results in a local denial of service on systems with ath11k when a privileged user configures bitrate masks.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 7, 2025
Updated Aug 5, 2026
Reserved Apr 16, 2025
NVD
Status Modified
Modified Jul 30, 2026
Red Hat
Severity Moderate
Public date Sep 7, 2025
ENISA EUVD
Assigner Linux
Published Sep 7, 2025
Updated Aug 5, 2026
Exploited since n/a
EUVD-2025-31498