Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()

There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
the parse infrastructure does not enforce a minimum length for the event
struct. Additionally, the num_vdevs field is taken directly from firmware
and used as a loop bound over the vdev_ids array without checking that it
fits within the TLV payload. Either condition can cause an out-of-bounds
read.

Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so
the parse infrastructure enforces a minimum length for the fixed-size event
struct. Add a helper ath12k_wmi_tlv_data_len() to recover the payload
length of a parsed TLV from the header preceding its data pointer. Use it
in ath12k_wmi_process_csa_switch_count_event() to bound num_vdevs before
the loop.

Compile tested only.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential information disclosure through out-of-bounds read
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the ath12k Wi‑Fi driver’s handling of the CSA switch count event. Because the driver did not enforce a minimum length on the event structure and used a firmware‑supplied count without validating that it fit within the TLV payload, it could read memory beyond the intended boundaries. This out‑of‑bounds read may expose sensitive data residing in kernel memory if the attacker can trigger the event. The patch adds a TLV policy entry and bounds the loop using the parsed payload length, preventing the overread.

Affected Systems

All Linux kernel installations that use the ath12k wireless driver may be affected. The specific kernel commit series referenced includes commits 878654e and bf97c9d. No particular kernel version range is listed, so any build that incorporates the driver code prior to the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the ability to craft and deliver a malformed WMI event to the target device, which typically entails privileged control over the Wi‑Fi firmware or a managed environment. Because the flaw only allows a read and does not provide code execution or privilege escalation paths, attackers may use it primarily for information gathering rather than direct system compromise.

Generated by OpenCVE AI on September 19, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the ath12k patch (e.g., after commit 878654e or bf97c9d).
  • If a vendor kernel cannot be upgraded immediately, rebuild the kernel with the patched ath12k source applied manually.
  • As a temporary measure, disable the ath12k driver or restrict processing of MI events until the kernel is patched.

Generated by OpenCVE AI on September 19, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event() There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so the parse infrastructure does not enforce a minimum length for the event struct. Additionally, the num_vdevs field is taken directly from firmware and used as a loop bound over the vdev_ids array without checking that it fits within the TLV payload. Either condition can cause an out-of-bounds read. Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so the parse infrastructure enforces a minimum length for the fixed-size event struct. Add a helper ath12k_wmi_tlv_data_len() to recover the payload length of a parsed TLV from the header preceding its data pointer. Use it in ath12k_wmi_process_csa_switch_count_event() to bound num_vdevs before the loop. Compile tested only.
Title wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:13.303Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90408

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.700

Modified: 2026-09-18T18:17:57.940

Link: CVE-2026-90408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses

No weakness.