CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's ath6kl Wi-Fi driver, specifically in the aggr_reset_state() function, which improperly handles a use-after-free condition due to asynchronous timer deletion. This flaw can lead to potential memory corruption and exploitation if the timer callback accesses freed memory, creating a race condition. Organizations using Linux systems with this driver should prioritize patching to mitigate risks associated with this vulnerability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy(). If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy(). Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.