Public bug reported:
[Impact]
On WCN7850 (FastConnect 7800, ath12k) adapters connected to an MLO
access point with more than one link, a firmware restart makes
ath12k_dp_rx_reo_cmd_list_cleanup() DMA-unmap and free the same REO
queue buffer once per link. The kernel logs a burst of WARNINGs in
iommu_dma_unmap_phys() and memory is corrupted. Tens of seconds later
unrelated subsystems crash.
On my system this happened twice on 7.0.0-34-generic:
1. Firmware restart, then 40 s later a kernel NULL pointer
dereference in zfs (zap_leaf_lookup) on the ZFS root, captured in
pstore.
2. Firmware restart, then about 11 minutes later a hard lockup with a
black screen and an unresponsive gnome-shell. The following warm
reboot hung before journald started; only a full power-off
recovered the machine.
The firmware restart was triggered by an ordinary disconnect/reconnect
(switching SSIDs with nmcli) while associated to a 3-link MLO AP
(6 GHz/320 MHz + 5 GHz + 2.4 GHz). The log shows:
ath12k_wifi7_pci 0000:4e:00.0: Timeout in receiving peer delete response
ath12k_wifi7_pci 0000:4e:00.0: failed to submit WMI_VDEV_DOWN cmd
ath12k_wifi7_pci 0000:4e:00.0: failed to down vdev 0: -108
followed by 33 of:
WARNING: drivers/iommu/dma-iommu.c:1243 at iommu_dma_unmap_phys+0xf2/0x100,
CPU#13: kworker/u192:0/12
Workqueue: ath12k_wq ath12k_core_restart [ath12k]
RIP: 0010:iommu_dma_unmap_phys+0xf2/0x100
Call Trace:
dma_unmap_phys+0x24a/0x340
dma_unmap_page_attrs+0x17/0x40
ath12k_dp_rx_reo_cmd_list_cleanup+0x147/0x260 [ath12k]
ath12k_dp_cmn_device_deinit+0xaa/0x150 [ath12k]
ath12k_core_restart+0x73/0x1e0 [ath12k]
and, in the first occurrence (pstore, 40 s after the restart):
BUG: kernel NULL pointer dereference, address: 0000000000000018
Oops: Oops: 0000 [#1] SMP NOPTI
CPU: 9 UID: 1000 PID: 101860 Comm: pool-96 Tainted: P W OE
7.0.0-34-generic #34-Ubuntu
RIP: 0010:zap_leaf_lookup+0x30/0x180 [zfs]
Any WCN7850 user on an MLO-capable (Wi-Fi 7) router is exposed. MLO is
the default on many current consumer routers.
[Fix]
Upstream commit, merged for v7.1 via wireless-2026-04-30:
4a1b534177395627579c1fb9e7f9100ee88955dd
"wifi: ath12k: prepare REO update element only for primary link"
Fixes: 3bf2e57e7d6c ("wifi: ath12k: Add Retry Mechanism for REO RX Queue
Update Failures")
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221011
Link:
https://patch.msgid.link/20260210-ath12k-rxtid-double-free-v1-1-8b523fb28...@oss.qualcomm.com
It was not tagged Cc: stable, so it never reached 7.0.y and is missing
from Ubuntu 7.0.0-34.34 (7.0.14 base). This was checked against the
linux-source-7.0.0 7.0.0-34.34 tree; the changelog does not mention it
either.
It is a 3-line change that applies cleanly to Ubuntu-7.0.0-34.34 (only
the context differs: kzalloc -> kzalloc_obj):
--- a/drivers/net/wireless/ath/ath12k/dp_rx.c
+++ b/drivers/net/wireless/ath/ath12k/dp_rx.c
@@ -565,6 +565,9 @@ static int ath12k_dp_prepare_reo_update_elem(struct
ath12k_dp *dp,
lockdep_assert_held(&dp->dp_lock);
+ if (!peer->primary_link)
+ return 0;
+
elem = kzalloc_obj(*elem, GFP_ATOMIC);
Please cherry-pick 4a1b53417739 into the Resolute kernels (generic,
generic-hwe, and the oem-26.04* kernels, which are also 7.0-based).
[Test Plan]
1. On a machine with a WCN7850 (17cb:1107), connect to a Wi-Fi 7 AP
with MLO enabled on 2 or more links (iw dev <if> link shows Link 0/1/2).
2. Repeatedly switch away from and back to the MLO SSID (nmcli
connection up <other>; nmcli connection up <mlo>) until a firmware
restart occurs ("Timeout in receiving peer delete response" /
ath12k_core_restart).
3. Unpatched: iommu_dma_unmap_phys WARNINGs from
ath12k_dp_rx_reo_cmd_list_cleanup, followed by memory corruption
and crashes in unrelated code.
Patched: the restart completes ("pdev 0 successfully recovered")
without WARNINGs and the system stays stable.
I built ath12k from linux-source-7.0.0 (7.0.0-34.34) with only this
patch applied, signed it with my MOK and loaded it on 7.0.0-34-generic.
It loads and works normally (157 Mbit/s on 6 GHz/320 MHz) with no
WARNINGs. Note: because of that, any logs attached after this point
show taint O from the out-of-tree test module. The two crashes above
happened with the stock in-tree ath12k (taint only from nvidia/zfs).
[Where problems could occur]
The change only affects the REO update-element bookkeeping for
non-primary link peers on chips without dp_primary_link_only (such as
WCN7850). Chips with dp_primary_link_only (QCN9274) already behaved
this way. A regression would show up as REO queue buffers for
non-primary links not being tracked for flush/retry, which in the
worst case could leak the buffer or stall RX on a secondary MLO link
after an REO update failure. Non-MLO (single-link) operation is
unaffected because every peer is then the primary link.
[Other info]
Hardware: ASUS ROG ZENITH II EXTREME ALPHA (BIOS 2502), Threadripper 3960X
Adapter: Qualcomm WCN785x Wi-Fi 7 [17cb:1107] rev 01,
subsystem Foxconn [105b:e0f7], PCIe add-in card
Firmware: WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
(linux-firmware 20260319.git217ca6e4.1ubuntu)
Kernel: Ubuntu 7.0.0-34.34-generic 7.0.14
AP: TP-Link Wi-Fi 7 router, MLO SSID with 6 GHz (320 MHz), 5 GHz
and 2.4 GHz links
Separate issue, not fixed by this patch: on the same MLO association,
RX throughput is about 0.5 Mbit/s versus 160+ Mbit/s on the same AP's
single-link 6 GHz SSID, while TX is fine. I can file this separately if
preferred.
ProblemType: Bug
DistroRelease: Ubuntu 26.04
Package: linux-image-7.0.0-34-generic 7.0.0-34.34
ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14
Uname: Linux 7.0.0-34-generic x86_64
NonfreeKernelModules: zfs
ApportVersion: 2.34.1-0ubuntu0.1
Architecture: amd64
CasperMD5CheckResult: unknown
CurrentDesktop: ubuntu:GNOME
Date: Wed Sep 30 21:36:13 2026
HibernationDevice: Error: [Errno 13] Permission denied:
'/etc/initramfs-tools/conf.d/resume'
InstallationDate: Installed on 2024-08-05 (787 days ago)
InstallationMedia: Ubuntu 24.04 LTS "Noble Numbat" - Release amd64 (20240424)
IwDevWlp74s0Link: Not connected.
MachineType: ASUS System Product Name
ProcFB: 0 nvidia-drmdrmfb
ProcKernelCmdLine: BOOT_IMAGE=/BOOT/ubuntu_dywk6g@/vmlinuz-7.0.0-34-generic
root=ZFS=rpool/ROOT/ubuntu_dywk6g ro quiet splash
crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M
SourcePackage: linux
UpgradeStatus: Upgraded to resolute on 2026-09-30 (0 days ago)
dmi.bios.date: 10/14/2025
dmi.bios.release: 25.2
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: 2502
dmi.board.asset.tag: Default string
dmi.board.name: ROG ZENITH II EXTREME ALPHA
dmi.board.vendor: ASUSTeK COMPUTER INC.
dmi.board.version: Rev 1.xx
dmi.chassis.asset.tag: Default string
dmi.chassis.type: 3
dmi.chassis.vendor: Default string
dmi.chassis.version: Default string
dmi.modalias:
dmi:bvnAmericanMegatrendsInc.:bvr2502:bd10/14/2025:br25.2:svnASUS:pnSystemProductName:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnROGZENITHIIEXTREMEALPHA:rvrRev1.xx:cvnDefaultstring:ct3:cvrDefaultstring:skuSKU:pfaTobefilledbyO.E.M.:
dmi.product.family: To be filled by O.E.M.
dmi.product.name: System Product Name
dmi.product.sku: SKU
dmi.product.version: System Version
dmi.sys.vendor: ASUS
** Affects: linux (Ubuntu)
Importance: Undecided
Status: New
** Tags: patch resolute
** Patch added:
"0001-ath12k-prepare-REO-update-element-only-for-primary-link.patch"
https://bugs.launchpad.net/bugs/2169101/+attachment/6004113/+files/0001-ath12k-prepare-REO-update-element-only-for-primary-link.patch
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169101
Title:
ath12k: WCN7850 MLO double DMA-unmap/free of REO queue buffer on
firmware restart corrupts memory (needs upstream 4a1b53417739)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2169101/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs