Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot

Since the hardware rfkill polling was introduced, arm64 platforms can
panic with an asynchronous SError during warm reboot:

SError Interrupt on CPU8, code 0x00000000be000011 -- SError
Workqueue: events_power_efficient rfkill_poll [rfkill]
rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci]
rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core]
rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core]
ieee80211_rfkill_poll+0x3c/0x70 [mac80211]
cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211]
rfkill_poll+0x30/0x88 [rfkill]
Kernel panic - not syncing: Asynchronous SError Interrupt

On the reboot path the kernel only runs device_shutdown(), which calls
each driver's .shutdown callback; .remove is not invoked. The rtw89 PCI
driver had no .shutdown callback, so nothing stopped the rfkill polling
work while the platform was tearing the PCIe link down. Once the link
is gone, the next MMIO read from the poll handler targets a
non-responding device and is reported as a fatal asynchronous SError on
arm64.

Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which
sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB
RTW89_FLAG_UNPLUGGED pattern). When the flag is set,
rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the
chip after shutdown begins and the SError no longer occurs.

This does not call the full .remove path from .shutdown, to keep the
shutdown handler minimal and avoid running the non-idempotent teardown
twice.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel panic (Denial of Service)
Action: Apply patch
AI Analysis

Impact

During a reboot on arm64 platforms, the rtw89 PCI wireless driver lacks a .shutdown callback. Askill polling work continues while the PCIe link is torn down, leading to asynchronous SError errors that trigger a kernel panic. The primary impact is a complete system halt, effectively a denial of service. This flaw is a classic case of improper cleanup of hardware resources, corresponding to CWE-772.

Affected Systems

The vulnerability applies to Linux kernel builds that include the rtw89 PCI driver on arm64 platforms. Specific kernel versions are not listed, so the affected range remains unspecified. Users of this driver should review the changelog for the update that kernel build contains the RTW89_FLAG_SHUTDOWN flag and the shutdown callback.

Risk and Exploitability

The flaw is triggered by any normal shutdown sequence invoking device_shutdown. Because the vulnerability activates only during the local shutdown process, remote attack is not possible. The EPSS score is < 1%, indicating a low exploitation probability, but the CVSS score of 4.7 reflects a moderate technical severity. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits exist. Until a kernel update or patch is applied, the risk is considered medium‑to‑high given the potential for system-wide interruption.

Generated by OpenCVE AI on September 21, 2026 at 02:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to shutdown fix.
  • If a stock kernel update is not yet available, apply the patch from the referenced kernel commit applied.
  • As a temporary mitigation, unload or disable the rtw89 PCI driver before rebooting to prevent rfkill polling during device teardown.

Generated by OpenCVE AI on September 21, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError Interrupt on CPU8, code 0x00000000be000011 -- SError Workqueue: events_power_efficient rfkill_poll [rfkill] rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci] rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core] rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core] ieee80211_rfkill_poll+0x3c/0x70 [mac80211] cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211] rfkill_poll+0x30/0x88 [rfkill] Kernel panic - not syncing: Asynchronous SError Interrupt On the reboot path the kernel only runs device_shutdown(), which calls each driver's .shutdown callback; .remove is not invoked. The rtw89 PCI driver had no .shutdown callback, so nothing stopped the rfkill polling work while the platform was tearing the PCIe link down. Once the link is gone, the next MMIO read from the poll handler targets a non-responding device and is reported as a fatal asynchronous SError on arm64. Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB RTW89_FLAG_UNPLUGGED pattern). When the flag is set, rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the chip after shutdown begins and the SError no longer occurs. This does not call the full .remove path from .shutdown, to keep the shutdown handler minimal and avoid running the non-idempotent teardown twice.
Title wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:03.269Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80939

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:58.553

Modified: 2026-09-14T13:18:50.037

Link: CVE-2026-80939

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:12Z

Links: CVE-2026-80939 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime