Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()

Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent
memcpy() destination advances by sizeof(full struct) per slot via C
pointer arithmetic, not by the clamped len. When firmware sends short
TLVs, the second and later slots are written past the end of the
allocation.

The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.

Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.

Compile tested only.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch immediately
AI Analysis

Impact

In the Linux kernel ath11k Wi‑Fi driver, a buffer intended to hold MAC PHY capability data is allocated with a size based on an incorrect stride calculation. When firmware transmits shorter-than‑expected TLVs, the subsequent memcpy writes past the end of the allocated buffer. This results in a heap overflow that corrupts kernel memory and could enable an attacker to overwrite critical kernel structures, potentially leading to arbitrary code execution at kernel privilege level. The weakness is a classic heap‑based buffer overflow.

Affected Systems

All Linux installations that include the ath11k driver and have not applied the patch. The affected code resides in the Linux kernel, specifically in the ath11k module. Any system using a kernel version that contains the vulnerable buffer allocation logic and receives firmware that can supply malformed TLVs is at risk.

Risk and Exploitability

The CVSS score of 8.4 classifies this as high severity. The EPSS score of <1% indicates low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. However, exploitation would require an attacker who can influence the Wi‑Fi firmware or craft malicious TLVs, typically via a local network or compromised device. The impact, if achieved, would be catastrophic kernel compromise. Given the low exploitation probability but high consequence, timely patching is advised.

Generated by OpenCVE AI on September 20, 2026 at 01:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the ath11k driver patch (commit 75185e2b or newer).
  • Disable or unload the ath11k module if an immediate kernel update is not possible to prevent driver loading.
  • Ensure Wi‑Fi firmware is up to date and validated; consider using vendor‑approved firmware images to reject malformed TLVs.

Generated by OpenCVE AI on September 20, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix stride mismatch in mac_phy_caps_parse() Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent memcpy() destination advances by sizeof(full struct) per slot via C pointer arithmetic, not by the clamped len. When firmware sends short TLVs, the second and later slots are written past the end of the allocation. The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the buffer with full-struct pointer arithmetic, so the allocation must match that stride. Fix by using kzalloc_objs(), which derives the element size from the pointer type, making allocation size and pointer stride provably consistent regardless of what len the firmware provides. Compile tested only.
Title wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:05.394Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90398

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.530

Modified: 2026-09-18T18:17:57.090

Link: CVE-2026-90398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow