Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()

Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The
subsequent memcpy() destination advances by sizeof(full struct) per slot
via C pointer arithmetic, not by the clamped len. When firmware sends
short TLVs, the second and later slots are written past the end of the
allocation.

The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.

Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption leading to potential Remote Code Execution
Action: Immediate Update
AI Analysis

Impact

The ath12k Wi‑Fi driver in the Linux kernel contains a buffer overflow bug in the mac_phy_caps_parse function. When firmware transmits shorter tables than expected, the driver allocates an array based on a clamped length but later copies data using the full structure size. This causes writes past the end of the allocated buffer, corrupting kernel memory. The vulnerability could be leveraged to crash the system or execute arbitrary code with kernel privileges, as reflected by a high CVSS score. The weakness is a classic buffer overflow (CWE-119/CWE-120).

Affected Systems

All Linux kernel systems that use the ath12k wireless driver are potentially affected. The exact kernel version is not specified, but the defect exists in the code path that parses MAC PHY capability tables. Users running unpatched kernels should evaluate whether their hardware uses the ath12k driver.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not listed in CISA KEV. Exploitability likely requires an attacker able to send crafted firmware or control packets to the ath12k driver, potentially from a remote Wi‑Fi network. Because the flaw leads to kernel memory corruption, successful exploitation could result in denial of service or privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 15:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the ath12k buffer‑overflow fix (e.g., kernel commit 26f8f87f0a556e7984366c64cebc16d49e15d22f or later).
  • Reboot the system after installing the updated kernel.
  • If a kernel update cannot be applied immediately, temporarily disable the ath12k driver to prevent the vulnerable code path from executing.

Generated by OpenCVE AI on September 19, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The subsequent memcpy() destination advances by sizeof(full struct) per slot via C pointer arithmetic, not by the clamped len. When firmware sends short TLVs, the second and later slots are written past the end of the allocation. The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the buffer with full-struct pointer arithmetic, so the allocation must match that stride. Fix by using kzalloc_objs(), which derives the element size from the pointer type, making allocation size and pointer stride provably consistent regardless of what len the firmware provides. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Title wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:06.735Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90399

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.643

Modified: 2026-09-18T18:17:57.220

Link: CVE-2026-90399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')