---
id: CVE-2024-58097
title: 'wifi: ath11k: fix RCU stall while reaping monitor destination ring'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: ath11k: fix RCU stall while reaping monitor destination ring

  While processing the monitor destination ring, MSDUs are reaped from the
  link descriptor based on th…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: adp
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    cdb32923699932502b0573f818643aae72ce0cd5
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    8db5de0cf02fccf4c759aa58edbe65659daf607c
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    9f1a002f0171d27f3554e529f3c70df438f05dfe
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    b4991fc41745645f8050506f5a8578bd11e6b378
  - >-
    Linux >= d5c65159f2895379e11ca13f62feabe93278985d <
    16c6c35c03ea73054a1f6d3302a4ce4a331b427d
  - Linux 5.6
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-10-01T17:05:53.896243Z'
published: '2025-04-16'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:57:50.395Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2024-58097'
references:
  - url: 'https://git.kernel.org/stable/c/cdb32923699932502b0573f818643aae72ce0cd5'
  - url: 'https://git.kernel.org/stable/c/8db5de0cf02fccf4c759aa58edbe65659daf607c'
  - url: 'https://git.kernel.org/stable/c/9f1a002f0171d27f3554e529f3c70df438f05dfe'
  - url: 'https://git.kernel.org/stable/c/b4991fc41745645f8050506f5a8578bd11e6b378'
  - url: 'https://git.kernel.org/stable/c/16c6c35c03ea73054a1f6d3302a4ce4a331b427d'
tags:
  - cve.org
epss: 0.00212
epssPercentile: 0.10216
ingestedAt: '2026-09-14T15:23:07.460Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix RCU stall while reaping monitor destination ring

While processing the monitor destination ring, MSDUs are reaped from the
link descriptor based on the corresponding buf_id.

However, sometimes the driver cannot obtain a valid buffer corresponding
to the buf_id received from the hardware. This causes an infinite loop
in the destination processing, resulting in a kernel crash.

kernel log:
ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309
ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed
ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309
ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed

Fix this by skipping the problematic buf_id and reaping the next entry,
replacing the break with the next MSDU processing.

Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1

## Affected

- `Linux >= d5c65159f2895379e11ca13f62feabe93278985d < cdb32923699932502b0573f818643aae72ce0cd5`
- `Linux >= d5c65159f2895379e11ca13f62feabe93278985d < 8db5de0cf02fccf4c759aa58edbe65659daf607c`
- `Linux >= d5c65159f2895379e11ca13f62feabe93278985d < 9f1a002f0171d27f3554e529f3c70df438f05dfe`
- `Linux >= d5c65159f2895379e11ca13f62feabe93278985d < b4991fc41745645f8050506f5a8578bd11e6b378`
- `Linux >= d5c65159f2895379e11ca13f62feabe93278985d < 16c6c35c03ea73054a1f6d3302a4ce4a331b427d`
- `Linux 5.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
