Re: [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit
From: Jeff Johnson
Date: Sun Oct 04 2026 - 11:17:21 EST
On 9/12/2026 1:23 AM, Toke Høiland-Jørgensen wrote:
> Rosen Penev <rosenp@xxxxxxxxx> writes:
>
>> ath9k_deinit_channel_context() cancels chanctx_work but does not delete
>> the offchannel and sched timers set up by ath9k_init_channel_context().
>> If either timer fires after deinit (e.g. during driver unload or
>> suspend), it accesses sc->sc_ah which may already be freed by
>> ath9k_hw_deinit(), causing a use-after-free.
>>
>> Delete both timers with timer_shutdown_sync() before cancelling the work
>> item.
>>
>> Assisted-by: LLM
>> Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
>
> Acked-by: Toke Høiland-Jørgensen <toke@xxxxxxx>
I'm picking this up now. Will add the following suggested by my review agent:
Fixes: 705d0bf83dbe ("ath9k: Add a routine for initializing channel contexts")
Cc: stable@xxxxxxxxxxxxxxx # v6.2+