{"id":"AZL-95018","summary":"CVE-2026-68408 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nWhen a netlink socket that owns a PMSR session is closed,\ncfg80211_release_pmsr() clears the request's nl_portid and queues\npmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.\n\nIf the interface tears down concurrently, cfg80211_pmsr_wdev_down()\nis called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk)\nto wait for any running work. The work function acquires wiphy_lock\nvia guard(wiphy) before calling process_abort.\n\nThis is a deadlock: wdev_down holds wiphy_lock and blocks inside\ncancel_work_sync(); pmsr_free_wk blocks trying to acquire that same\nwiphy_lock. Neither thread can proceed.\n\nThe same deadlock is reachable from cfg80211_leave_locked(), which\ncalls cfg80211_pmsr_wdev_down() for all interface types under\nwiphy_lock.\n\nFix this by converting pmsr_free_wk from a plain work_struct to a\nwiphy_work. The wiphy_work dispatcher holds wiphy_lock when running\nwork items, so the explicit guard(wiphy) in the work function is no\nlonger needed. wiphy_work_cancel() can be called safely while holding\nwiphy_lock - since wiphy_lock prevents the work from running\nconcurrently, wiphy_work_cancel() never blocks, eliminating the\ndeadlock.\n\nRemove the cancel_work_sync() for pmsr_free_wk from the\nNETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally\njust before it, already cancels any pending work under wiphy_lock\nvia wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().","modified":"2026-09-01T05:28:09Z","published":"2026-08-10T13:20:34Z","upstream":["CVE-2026-68408"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68408"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95018.json"}}],"schema_version":"1.9.0"}