Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump

On WCN3990/SNOC the MSA region is mapped with devm_memremap(MEMREMAP_WT).
On arm64 such a mapping is not Normal-cacheable, so unaligned accesses to
it are not permitted. ath10k_msa_dump_memory() copies the region with a
plain memcpy(), whose optimized __pi_memcpy_generic implementation issues
wide/unaligned loads. This triggers an alignment fault (FSC=0x21) Oops in
ath10k_snoc_fw_crashed_dump() while collecting the devcoredump:

Unable to handle kernel paging request ... FSC=0x21: alignment fault
pc : __pi_memcpy_generic
lr : ath10k_snoc_fw_crashed_dump [ath10k_snoc]

The Oops both leaves the firmware RAM dump buffer zeroed (no dump is
captured) and crashes the kernel, which in turn breaks modem SSR
recovery.

Use memcpy_fromio(), which only performs accesses that are valid for such
a device-memory mapping. The generic memcpy_fromio() implementation aligns
the source before issuing word-sized reads and stores the destination with
put_unaligned(), so it is also safe for the coherent DMA allocation used on
the non-reserved-memory path. ath11k and ath12k use the same pattern
when copying target memory into crash dumps, so call it unconditionally
here too.
The MEMREMAP_WT pointer is a plain void *, so an explicit __iomem cast is
needed; use __force to keep sparse happy.

Tested-on: WCN3990 hw1.0 SNOC WLAN.HL.3.3.7.c5-00107-QCAHLSWMTPL-1
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash and denial of service
Action: Patch Kernel
AI Analysis

Impact

The vulnerability resides in the Linux wireless driver ath10k, where the firmware crash‑dump routine copies the MSA memory region using the generic memcpy function. On arm64 platforms, this memory tier is mapped with devm_memremap(MEMREMAP_WT) and is not normal‑cacheable, meaning unaligned accesses are prohibited. The generic memcpy implementation performs wide, unaligned loads. When this code path is executed, an alignment fault (FSC=0x21) is raised, causing an Oops that crashes the kernel and leaves the firmware RAM dump buffer empty, thereby breaking modem self‑recovery.

Affected Systems

This defect impacts Linux kernels that include the ath10k driver before the patch that replaces memcpy with memcpy_fromio. The bug is specifically relevant to the WCN3990/SNOC WLAN hardware on arm64 machines, as demonstrated in the test environment identified in the advisory. No explicit version range is provided, so any kernel release incorporating the original code path is considered vulnerable until the commit that introduces memcpy_fromio is merged.

Risk and Exploitability

The EPSS score for this CVE is below 1 %, and it is not listed in the CISA KEV catalog, suggesting a low probability of public exploitation at present. However, the bug can cause a kernel crash and denial of service in affected systems; the damage is local but can lead to a loss of modem functionality if the crash occurs during a firmware failure. Because the trigger is the crash‑dump routine, an attacker would need to provoke a firmware crash or manipulate driver behaviour, which may be feasible if firmware can be controlled or via privileged local access.

Generated by OpenCVE AI on September 19, 2026 at 04:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the ath10k commit applying memcpy_fromio for the MSA ramdump (e.g., kernel commit 045d1bfb72d2631ab9ec74afa491aa788ebb57aa).
  • Reboot the system after the update to ensure the WLAN driver is reloaded with the corrected code path.
  • If an immediate kernel upgrade is not possible, temporarily disable the ath10k crash‑dump feature or prevent the firmware from invoking the MSA dump routine (for example, by setting a kernel parameter or patching the driver in a local dev environment).

Generated by OpenCVE AI on September 19, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump On WCN3990/SNOC the MSA region is mapped with devm_memremap(MEMREMAP_WT). On arm64 such a mapping is not Normal-cacheable, so unaligned accesses to it are not permitted. ath10k_msa_dump_memory() copies the region with a plain memcpy(), whose optimized __pi_memcpy_generic implementation issues wide/unaligned loads. This triggers an alignment fault (FSC=0x21) Oops in ath10k_snoc_fw_crashed_dump() while collecting the devcoredump: Unable to handle kernel paging request ... FSC=0x21: alignment fault pc : __pi_memcpy_generic lr : ath10k_snoc_fw_crashed_dump [ath10k_snoc] The Oops both leaves the firmware RAM dump buffer zeroed (no dump is captured) and crashes the kernel, which in turn breaks modem SSR recovery. Use memcpy_fromio(), which only performs accesses that are valid for such a device-memory mapping. The generic memcpy_fromio() implementation aligns the source before issuing word-sized reads and stores the destination with put_unaligned(), so it is also safe for the coherent DMA allocation used on the non-reserved-memory path. ath11k and ath12k use the same pattern when copying target memory into crash dumps, so call it unconditionally here too. The MEMREMAP_WT pointer is a plain void *, so an explicit __iomem cast is needed; use __force to keep sparse happy. Tested-on: WCN3990 hw1.0 SNOC WLAN.HL.3.3.7.c5-00107-QCAHLSWMTPL-1
Title wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:56.885Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.553

Modified: 2026-09-17T17:17:33.553

Link: CVE-2026-90348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:30:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-20

    Improper Input Validation