Kernel Vulnerability Affecting Linux with Ath11k PCI Devices
CVE-2026-74407

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74407?

A vulnerability in the Ath11k PCI driver within the Linux kernel can lead to a system crash during reboot if it coincides with WLAN firmware crash recovery. This is due to a NULL pointer dereference occurring in the MHI teardown path as DMA-backed MHI resources are being freed. The issue arises when the shutdown process runs asynchronously with the recovery sequence managed by the MHI RDDM callback, potentially resulting in a race condition. Proper mitigation involves canceling SSR-related work items before executing PCI shutdown, ensuring device state is appropriately managed and preventing multiple executions of resource deallocation.

Affected Version(s)

Linux 13da397f884d9c9a3fb6616206eeb6c6ab097287 < 53dd29e8aeb2a1b5f079178551836b85fc6b53df

Linux 13da397f884d9c9a3fb6616206eeb6c6ab097287 < 8c79aac429b583301f387374ff37c59be671df87

Linux 5.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.