Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix leak in ath11k_service_ready_ext_event()

Currently, during ath11k_service_ready_ext_event() processing,
svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
temporary allocation that is freed on the success path, but not on the
error path. If parsing succeeds far enough to allocate mac_phy_caps and
then fails on a later TLV, the allocation leaks. So free the allocation
on the error path.

Compile tested only.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Memory Exhaustion)
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises in the ath11k Wi‑Fi driver when the ath11k_service_ready_ext_event() routine allocates mac_phy_caps during parsing of TLVs but fails to free that allocation when a later parsing step fails. The resulting memory leak can gradually consume kernel memory, potentially destabilizing the system or causing a crash. The weakness is an improper resource management flaw, which could be leveraged by an attacker who can inject or influence the TLV stream to provoke the failure path.

Affected Systems

The affected products are Linux kernel builds that include the ath11k Wi‑Fi driver and have not yet incorporated the commit that fixes the memory leak. No specific kernel version range is listed, so all current kernels that use ath11k before the patch are considered vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, indicating a low probability that the vulnerability will be actively exploited. It is not listed in the CISA KEV catalog. Because the CVE description only mentions parsing of TLVs and leaks on error, it does not explicitly state how an attacker would trigger the failure path; thus the likely attack requires sending crafted Wi‑Fi frames to the ath11k driver, which is inferred from typical Wi‑Fi driver behaviour. The exact vector is not documented in the CVE text, so this inference is based on the driver’s role in processing frames. Without direct privilege escalation, the attack would probably result only in local denial of service, and the overall risk is moderate for systems that rely on ath11k Wi‑Fi connectivity.

Generated by OpenCVE AI on September 19, 2026 at 14:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the ath11k_service_ready_ext_event() fix
  • If an immediate kernel update is not possible, disable or unload the ath11k driver to prevent the memory leak
  • Monitor system memory usage for unexpected growth and consider limiting swap or setting appropriate kernel memory limits to mitigate potential DoS

Generated by OpenCVE AI on September 19, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Currently, during ath11k_service_ready_ext_event() processing, svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a temporary allocation that is freed on the success path, but not on the error path. If parsing succeeds far enough to allocate mac_phy_caps and then fails on a later TLV, the allocation leaks. So free the allocation on the error path. Compile tested only.
Title wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:05.505Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90361

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:35.073

Modified: 2026-09-17T17:17:35.073

Link: CVE-2026-90361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime