CVE-2026-64175
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
wifi: iwlwifi: mld: stop TX tijdens herstart firmware
Wanneer iwlwifi firmware crasht (bijv. NMI_INTERRUPT_UNKNOWN op Intel
BE201/Wi-Fi 7), iwl_mld_nic_error() sets mld->fw_status.in_hw_restart
tot waar. Echter, iwl_mld_tx_from_txq () controleert deze vlag niet voor
het verwijderen van frames uit mac80211 en deze naar de transportlaag te duwen. Aangezien de firmware dood is, retourneert iwl_trans_tx() -EIO voor elk frame,
die dan meteen vrijkomt. Onder omstandigheden met een hoge doorvoer
(bijv. UDP-verkeer op maat of actieve SSH-sessies), dit creëert een
strakke dequeue-verzenden-foutvrije lus die CPU-cycli verspilt en genereert
snelle skb-allocatie churn, wat leidt tot geheugendruk van de plaat
fragmentatie. Het RX-pad heeft deze bewaker al (iwl_mld_rx_mpdu controles
in_hw_restart at rx.c:1906), net als de TXQ-allocatiemedewerker
(iwl_mld_add_txqs_wk op tx.c:156). Voeg dezelfde beschermkap toe aan
iwl_mld_tx_from_txq () om alle TX te stoppen tijdens het herstarten van de firmware. Frames die achterblijven in de TXQ's van mac80211 worden na het opnieuw opstarten op natuurlijke wijze leeggemaakt
voltooid, wanneer opnieuw toewijzen van wachtrijen iwl_mld_tx_from_txq () activeert
via iwl_mld_add_txq_list(), of wanneer nieuw verkeer uit de bovenste laag wordt opgeroepen
wake_tx_queue. Getest op ASUS Zenbook 14 UX3405CA met Intel BE201 (Wi-Fi 7) op
kernel 6.19.5 waar de firmware ongeveer elke 10-15 crasht
minuten onder Staartschaalverkeer.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: stop TX during firmware restart
When iwlwifi firmware crashes (e.g., NMI_INTERRUPT_UNKNOWN on Intel
BE201/Wi-Fi 7), iwl_mld_nic_error() sets mld->fw_status.in_hw_restart
to true. However, iwl_mld_tx_from_txq() does not check this flag before
dequeuing frames from mac80211 and pushing them to the transport layer.
Since the firmware is dead, iwl_trans_tx() returns -EIO for each frame,
which then gets freed immediately. Under high-throughput conditions
(e.g., Tailscale UDP traffic or active SSH sessions), this creates a
tight dequeue-send-fail-free loop that wastes CPU cycles and generates
rapid skb allocation churn, leading to memory pressure from slab
fragmentation.
The RX path already has this guard (iwl_mld_rx_mpdu checks
in_hw_restart at rx.c:1906), and so does the TXQ allocation worker
(iwl_mld_add_txqs_wk at tx.c:156). Add the same guard to
iwl_mld_tx_from_txq() to stop all TX during firmware restart.
Frames left in mac80211's TXQs are naturally drained after restart
completes, when queue reallocation triggers iwl_mld_tx_from_txq()
via iwl_mld_add_txq_list(), or when new upper-layer traffic invokes
wake_tx_queue.
Tested on ASUS Zenbook 14 UX3405CA with Intel BE201 (Wi-Fi 7) on
kernel 6.19.5 where the firmware crashes approximately every 10-15
minutes under Tailscale traffic.