From nobody Mon Sep 28 13:19:01 2026 Received: from mail-4325.protonmail.ch (mail-4325.protonmail.ch [185.70.43.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17E3547AF63 for ; Fri, 21 Aug 2026 10:40:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.70.43.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787308834; cv=none; b=nejpQBE0dZKc9iJ3npw/nWdp80IgPkxQbru/NgxklBt6tgcN3QHlR9P3TCyQCljxdyyhrVjzqt1qbpO4pPlOWwnKjaviumLjwru3OEm3HMq6khDnaQH4jGSTXsXK8rq5oKhW04u6RggJ3T4o79OBwZkyeEp8Beu1hc/fdNPfQ34= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787308834; c=relaxed/simple; bh=q1cswTBQwlfyKLjgpL/0p/xOuHzHelUpb/0O/Tv/eGo=; h=Date:To:From:Cc:Subject:Message-ID:MIME-Version:Content-Type; b=UdW2wpu69iqJVL0tISRk7SPFEXXqv+a9vJ4aTzhIUa3NQrLkZm9sWWPS+xMDDNCea+PNcrLO1xeGetrClUlj18pg1Cd97VS/zvThVPRBYPXFiiWm3awPHc3YmTKfQYeQMaWxcsvVPIvCF9GSc9WMW1lIShXAO13YAVmxDWXylaQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com; spf=pass smtp.mailfrom=protonmail.com; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b=a23QH3JP; arc=none smtp.client-ip=185.70.43.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=protonmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b="a23QH3JP" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1787308823; x=1787568023; bh=q1cswTBQwlfyKLjgpL/0p/xOuHzHelUpb/0O/Tv/eGo=; h=Date:To:From:Cc:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=a23QH3JPSszQ13w6n0oiuoHgBRAQHbon7SzTKxP9V/uxWtwJU/wZ7TrAOCo3g43gT Y7v7yp4lJ6HqVCcmcHo4ML2mZSQLxH6IZ5VaxKAH6BZFTGNVaAZuPu75EJv5I2zhGD o34NUq1SNPSPJzkfaJ3PxRm/7XAQjRSW9OI4BRDHxTqk0QQ1hgzweu/X/cQWjCWO4K 0brCshKKN6jO4/4azjTk733D7cdtlY5DugvAc2iVNx74nsg3gNd60mS685t3l7lzil tmQuOcm4gPj7qHoxj+zmBNyNgE7CB1eOi4DFlHth3JjEtn/ke29zbR+O7W3R00rhx4 U/PvaoMiZ/DBg== Date: Fri, 21 Aug 2026 10:40:18 +0000 To: Felix Fietkau , Lorenzo Bianconi , Ryder Lee , Shayne Chen , Sean Wang , Matthias Brugger , AngeloGioacchino Del Regno From: Ryan Leung Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, Ryan Leung Subject: [PATCH] wifi: mt76: fix unlocked wcid check in mt76_tx_status_skb_add() Message-ID: <20260821-mt76-stale-wcid-race-v1-1-d6de3f842506@protonmail.com> Feedback-ID: 184418679:user:proton X-Pm-Message-ID: 020a7b2af528b10c02e7f3b790153a0ef2cff700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mt76_tx_status_skb_add() checks rcu_access_pointer(dev->wcid[wcid->idx]) before taking dev->status_lock, then allocates a pktid afterwards. A concurrent mt76_wcid_cleanup() can run between the check and the lock, letting a stale wcid be re-added to dev->wcid_list after teardown. Move the check inside the status_lock section, so that it is atomic with the idr_alloc() and wcid_list update. Fixes: fcfe1b5e162b ("mt76: fix tx status related use-after-free race on st= ation removal") Signed-off-by: Ryan Leung --- drivers/net/wireless/mediatek/mt76/tx.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/mediatek/mt76/tx.c b/drivers/net/wireless= /mediatek/mt76/tx.c index 3707ee19e4ae..fa635fe84ec2 100644 --- a/drivers/net/wireless/mediatek/mt76/tx.c +++ b/drivers/net/wireless/mediatek/mt76/tx.c @@ -129,7 +129,7 @@ mt76_tx_status_skb_add(struct mt76_dev *dev, struct mt7= 6_wcid *wcid, =20 memset(cb, 0, sizeof(*cb)); =20 - if (!wcid || !rcu_access_pointer(dev->wcid[wcid->idx])) + if (!wcid) return MT_PACKET_ID_NO_ACK; =20 if (info->flags & IEEE80211_TX_CTL_NO_ACK) @@ -147,6 +147,11 @@ mt76_tx_status_skb_add(struct mt76_dev *dev, struct mt= 76_wcid *wcid, =20 spin_lock_bh(&dev->status_lock); =20 + if (!rcu_access_pointer(dev->wcid[wcid->idx])) { + pid =3D MT_PACKET_ID_NO_ACK; + goto out; + } + pid =3D idr_alloc(&wcid->pktid, skb, MT_PACKET_ID_FIRST, MT_PACKET_ID_MASK, GFP_ATOMIC); if (pid < 0) { --- base-commit: ca800a9302764c445de0da0e84d2252400a770ee change-id: 20260821-mt76-stale-wcid-race-4d92f898437b Best regards, -- =20 Ryan Leung