Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: avoid buffer overreads in WMI event handlers

The following WMI event handlers currently read from the event buffer
without first verifying that the message was large enough to hold the
expected event:
ath6kl_wmi_scan_complete_rx()
ath6kl_wmi_addba_req_event_rx()
ath6kl_wmi_delba_req_event_rx()

Add length checks to prevent overread.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Buffer Overread in the Linux ath6kl driver potentially exposes kernel memory contents
Action: Immediate Patch
AI Analysis

Impact

The ath6kl driver for Wi‑Fi hardware in the Linux kernel contains functions that read event data from the WMI buffer without checking that the data is long enough. When a message is smaller than expected, the driver overreads kernel memory. Depending on how the attacker can supply WMI messages, this could leak confidential data or trigger a crash, impacting confidentiality and availability.

Affected Systems

This flaw affects all Linux systems whose kernel includes the ath6kl wireless driver. No specific kernel releases are listed, so every distribution that ships the driver in the kernel is potentially affected until the patch is applied.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The bug resides in kernel‑space code, so an attacker would need the ability to send crafted WMI messages to the ath6kl device, which may require privileged firmware access or physical proximity. The CVSS score is not provided, but the lack of external exploitation data and the local nature of the vulnerability suggest a moderate risk if an attacker can meet the prerequisites.

Generated by OpenCVE AI on September 19, 2026 at 09:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the ath6kl patch that added length checks in the event handlers.
  • Ensure the kernel module is reloaded after the upgrade so that the updated code takes effect.
  • If a kernel upgrade cannot be performed immediately, disable or remove the ath6kl driver or block WMI traffic to the device until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-127

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event handlers The following WMI event handlers currently read from the event buffer without first verifying that the message was large enough to hold the expected event: ath6kl_wmi_scan_complete_rx() ath6kl_wmi_addba_req_event_rx() ath6kl_wmi_delba_req_event_rx() Add length checks to prevent overread.
Title wifi: ath6kl: avoid buffer overreads in WMI event handlers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:12.732Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92498

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:52.147

Modified: 2026-09-17T17:17:52.147

Link: CVE-2026-92498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:15:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-127

    Buffer Under-read