Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()

Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without
first verifying that the buffer has enough data to hold a header. This
could result in a buffer overread.

Update the logic to verify the buffer contains at least enough data to
hold a wmi_cmd_hdr before reading from the buffer.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Buffer Overread
Action: Patch kernel
AI Analysis

Impact

The flaw triggers when the ath12k Wi‑Fi driver reads a firmware buffer without first confirming that the buffer contains at least the size required for a wmi_cmd_hdr. This unchecked bounds check can cause a buffer overread, potentially allowing the driver to read unintended memory locations and crash the kernel. The vulnerability does not expose additional network traffic or channels beyond this memory access.

Affected Systems

Linux kernel builds that include the ath12k driver, particularly those running Qualcomm Atheros hardware such as the WCN7850. No specific kernel version is enumerated, so any kernel containing a vulnerable ath12k module may be affected.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation at this time. No public exploits are documented. Exploitation would likely require an attacker to supply malicious firmware or otherwise influence the driver’s communication with the device, which generally requires local or privileged access. The potential impact is limited to kernel crashes or unintended memory reads; the overall risk remains low unless a targeted exploit is discovered.

Generated by OpenCVE AI on September 19, 2026 at 13:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the patched ath12k driver, or apply the upstream commit referenced in the advisory.
  • If a kernel upgrade is not possible, blacklist or unload the ath12k module to prevent the driver from loading.
  • Verify that the firmware for Qualcomm Atheros Wi‑Fi hardware is from a trusted source and has not been tampered with.
  • Monitor system logs (e.g., dmesg, /var/log/kern.log) for signs of Wi‑Fi driver crashes or abnormal memory accesses indicating exploitation.

Generated by OpenCVE AI on September 19, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread. Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Title wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:12.081Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:52.033

Modified: 2026-09-17T17:17:52.033

Link: CVE-2026-92497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer