Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()

There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
the parse infrastructure does not enforce a minimum length for the event
struct. Additionally, the num_vdevs field is taken directly from firmware
and used as a loop bound over the vdev_ids array without checking that it
fits within the TLV payload. Either condition can cause an out-of-bounds
read.

Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so
the parse infrastructure enforces a minimum length for the fixed-size event
struct. Add a helper ath11k_wmi_tlv_data_len() to recover the payload
length of a parsed TLV from the header preceding its data pointer. Use it
in ath11k_wmi_process_csa_switch_count_event() to bound num_vdevs before
the loop.

Compile tested only.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The kernel driver for ath11k wireless chipsets has an unchecked loop bound that allows an arbitrary out-of-bounds read of kernel memory. The number of virtual devices reported by firmware is used directly as a bound on an array without verifying it fits within the received data, which can cause the kernel to read beyond the intended buffer and expose kernel memory contents.

Affected Systems

Linux systems that load the ath11k driver are potentially affected. Based on the description, it is inferred that Qualcomm Atheros QCA99x0 or similar 802.11ac/802.11ax wireless hardware could be the target. Any kernel build including the ath11k driver before the patch that adds a TLV policy entry and bounds size validation is potentially affected.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. The EPSS score of less than 1 % suggests a very low likelihood of active exploitation at this time. The vulnerability is not listed in CISA KEV. An attacker would need to influence the driver to process a crafted WMI event, which typically requires local or privileged access, making remote exploitation unlikely without additional conditions.

Generated by OpenCVE AI on September 20, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the ath11k driver patch
  • If an update is not available, disable or unload the ath11k module or turn off the wireless interface
  • Monitor system logs for anomalous memory access errors or crashes that could indicate exploitation attempts

Generated by OpenCVE AI on September 20, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 00:15:00 +0000


Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infrastructure does not enforce a minimum length for the event struct. Additionally, the num_vdevs field is taken directly from firmware and used as a loop bound over the vdev_ids array without checking that it fits within the TLV payload. Either condition can cause an out-of-bounds read. Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so the parse infrastructure enforces a minimum length for the fixed-size event struct. Add a helper ath11k_wmi_tlv_data_len() to recover the payload length of a parsed TLV from the header preceding its data pointer. Use it in ath11k_wmi_process_csa_switch_count_event() to bound num_vdevs before the loop. Compile tested only.
Title wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:12.082Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90407

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.573

Modified: 2026-09-18T18:17:57.790

Link: CVE-2026-90407

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-90407 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses