Public bug reported:

[Impact]

On WCN7850 (FastConnect 7800, ath12k) adapters connected to an MLO
access point with more than one link, a firmware restart makes
ath12k_dp_rx_reo_cmd_list_cleanup() DMA-unmap and free the same REO
queue buffer once per link. The kernel logs a burst of WARNINGs in
iommu_dma_unmap_phys() and memory is corrupted. Tens of seconds later
unrelated subsystems crash.

On my system this happened twice on 7.0.0-34-generic:

 1. Firmware restart, then 40 s later a kernel NULL pointer
    dereference in zfs (zap_leaf_lookup) on the ZFS root, captured in
    pstore.
 2. Firmware restart, then about 11 minutes later a hard lockup with a
    black screen and an unresponsive gnome-shell. The following warm
    reboot hung before journald started; only a full power-off
    recovered the machine.

The firmware restart was triggered by an ordinary disconnect/reconnect
(switching SSIDs with nmcli) while associated to a 3-link MLO AP
(6 GHz/320 MHz + 5 GHz + 2.4 GHz). The log shows:

  ath12k_wifi7_pci 0000:4e:00.0: Timeout in receiving peer delete response
  ath12k_wifi7_pci 0000:4e:00.0: failed to submit WMI_VDEV_DOWN cmd
  ath12k_wifi7_pci 0000:4e:00.0: failed to down vdev 0: -108

followed by 33 of:

  WARNING: drivers/iommu/dma-iommu.c:1243 at iommu_dma_unmap_phys+0xf2/0x100, 
CPU#13: kworker/u192:0/12
  Workqueue: ath12k_wq ath12k_core_restart [ath12k]
  RIP: 0010:iommu_dma_unmap_phys+0xf2/0x100
  Call Trace:
   dma_unmap_phys+0x24a/0x340
   dma_unmap_page_attrs+0x17/0x40
   ath12k_dp_rx_reo_cmd_list_cleanup+0x147/0x260 [ath12k]
   ath12k_dp_cmn_device_deinit+0xaa/0x150 [ath12k]
   ath12k_core_restart+0x73/0x1e0 [ath12k]

and, in the first occurrence (pstore, 40 s after the restart):

  BUG: kernel NULL pointer dereference, address: 0000000000000018
  Oops: Oops: 0000 [#1] SMP NOPTI
  CPU: 9 UID: 1000 PID: 101860 Comm: pool-96 Tainted: P        W  OE       
7.0.0-34-generic #34-Ubuntu
  RIP: 0010:zap_leaf_lookup+0x30/0x180 [zfs]

Any WCN7850 user on an MLO-capable (Wi-Fi 7) router is exposed. MLO is
the default on many current consumer routers.

[Fix]

Upstream commit, merged for v7.1 via wireless-2026-04-30:

  4a1b534177395627579c1fb9e7f9100ee88955dd
  "wifi: ath12k: prepare REO update element only for primary link"
  Fixes: 3bf2e57e7d6c ("wifi: ath12k: Add Retry Mechanism for REO RX Queue 
Update Failures")
  Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221011
  Link: 
https://patch.msgid.link/20260210-ath12k-rxtid-double-free-v1-1-8b523fb28...@oss.qualcomm.com

It was not tagged Cc: stable, so it never reached 7.0.y and is missing
from Ubuntu 7.0.0-34.34 (7.0.14 base). This was checked against the
linux-source-7.0.0 7.0.0-34.34 tree; the changelog does not mention it
either.

It is a 3-line change that applies cleanly to Ubuntu-7.0.0-34.34 (only
the context differs: kzalloc -> kzalloc_obj):

  --- a/drivers/net/wireless/ath/ath12k/dp_rx.c
  +++ b/drivers/net/wireless/ath/ath12k/dp_rx.c
  @@ -565,6 +565,9 @@ static int ath12k_dp_prepare_reo_update_elem(struct 
ath12k_dp *dp,
        lockdep_assert_held(&dp->dp_lock);
   
  +     if (!peer->primary_link)
  +             return 0;
  +
        elem = kzalloc_obj(*elem, GFP_ATOMIC);

Please cherry-pick 4a1b53417739 into the Resolute kernels (generic,
generic-hwe, and the oem-26.04* kernels, which are also 7.0-based).

[Test Plan]

 1. On a machine with a WCN7850 (17cb:1107), connect to a Wi-Fi 7 AP
    with MLO enabled on 2 or more links (iw dev <if> link shows Link 0/1/2).
 2. Repeatedly switch away from and back to the MLO SSID (nmcli
    connection up <other>; nmcli connection up <mlo>) until a firmware
    restart occurs ("Timeout in receiving peer delete response" /
    ath12k_core_restart).
 3. Unpatched: iommu_dma_unmap_phys WARNINGs from
    ath12k_dp_rx_reo_cmd_list_cleanup, followed by memory corruption
    and crashes in unrelated code.
    Patched: the restart completes ("pdev 0 successfully recovered")
    without WARNINGs and the system stays stable.

I built ath12k from linux-source-7.0.0 (7.0.0-34.34) with only this
patch applied, signed it with my MOK and loaded it on 7.0.0-34-generic.
It loads and works normally (157 Mbit/s on 6 GHz/320 MHz) with no
WARNINGs. Note: because of that, any logs attached after this point
show taint O from the out-of-tree test module. The two crashes above
happened with the stock in-tree ath12k (taint only from nvidia/zfs).

[Where problems could occur]

The change only affects the REO update-element bookkeeping for
non-primary link peers on chips without dp_primary_link_only (such as
WCN7850). Chips with dp_primary_link_only (QCN9274) already behaved
this way. A regression would show up as REO queue buffers for
non-primary links not being tracked for flush/retry, which in the
worst case could leak the buffer or stall RX on a secondary MLO link
after an REO update failure. Non-MLO (single-link) operation is
unaffected because every peer is then the primary link.

[Other info]

Hardware:  ASUS ROG ZENITH II EXTREME ALPHA (BIOS 2502), Threadripper 3960X
Adapter:   Qualcomm WCN785x Wi-Fi 7 [17cb:1107] rev 01,
           subsystem Foxconn [105b:e0f7], PCIe add-in card
Firmware:  WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
           (linux-firmware 20260319.git217ca6e4.1ubuntu)
Kernel:    Ubuntu 7.0.0-34.34-generic 7.0.14
AP:        TP-Link Wi-Fi 7 router, MLO SSID with 6 GHz (320 MHz), 5 GHz
           and 2.4 GHz links

Separate issue, not fixed by this patch: on the same MLO association,
RX throughput is about 0.5 Mbit/s versus 160+ Mbit/s on the same AP's
single-link 6 GHz SSID, while TX is fine. I can file this separately if
preferred.

ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: linux-image-7.0.0-34-generic 7.0.0-34.34
ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14
Uname: Linux 7.0.0-34-generic x86_64
NonfreeKernelModules: zfs
ApportVersion: 2.34.1-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: unknown
CurrentDesktop: ubuntu:GNOME
Date: Wed Sep 30 21:36:13 2026
HibernationDevice: Error: [Errno 13] Permission denied: 
'/etc/initramfs-tools/conf.d/resume'
InstallationDate: Installed on 2024-08-05 (787 days ago)
InstallationMedia: Ubuntu 24.04 LTS "Noble Numbat" - Release amd64 (20240424)
IwDevWlp74s0Link: Not connected.
MachineType: ASUS System Product Name
ProcFB: 0 nvidia-drmdrmfb
ProcKernelCmdLine: BOOT_IMAGE=/BOOT/ubuntu_dywk6g@/vmlinuz-7.0.0-34-generic 
root=ZFS=rpool/ROOT/ubuntu_dywk6g ro quiet splash 
crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M
SourcePackage: linux
UpgradeStatus: Upgraded to resolute on 2026-09-30 (0 days ago)
dmi.bios.date: 10/14/2025
dmi.bios.release: 25.2
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: 2502
dmi.board.asset.tag: Default string
dmi.board.name: ROG ZENITH II EXTREME ALPHA
dmi.board.vendor: ASUSTeK COMPUTER INC.
dmi.board.version: Rev 1.xx
dmi.chassis.asset.tag: Default string
dmi.chassis.type: 3
dmi.chassis.vendor: Default string
dmi.chassis.version: Default string
dmi.modalias: 
dmi:bvnAmericanMegatrendsInc.:bvr2502:bd10/14/2025:br25.2:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGZENITHIIEXTREMEALPHA:rvrRev1.xx:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.:
dmi.product.family: To be filled by O.E.M.
dmi.product.name: System Product Name
dmi.product.sku: SKU
dmi.product.version: System Version
dmi.sys.vendor: ASUS

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: patch resolute

** Patch added: 
"0001-ath12k-prepare-REO-update-element-only-for-primary-link.patch"
   
https://bugs.launchpad.net/bugs/2169101/+attachment/6004113/+files/0001-ath12k-prepare-REO-update-element-only-for-primary-link.patch

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169101

Title:
  ath12k: WCN7850 MLO double DMA-unmap/free of REO queue buffer on
  firmware restart corrupts memory (needs upstream 4a1b53417739)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169101/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to