CVE-2026-92496

high

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Currently, in ath11k_wmi_tlv_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread. Add an upfront length check before dereferencing skb->data as a wmi_cmd_hdr. The check is placed before the trace_ath11k_wmi_event() call to preserve the existing trace semantics (tracing the full raw WMI event including the header), unlike the analogous ath12k fix which could use skb_pull_data() directly. Compile tested only.

References

https://git.kernel.org/stable/c/f9726f6d97dca94ab14739c8b632301a940a7e8f

https://git.kernel.org/stable/c/9ef9dd30058cc9223c72f711dca1a28a5947d0c5

https://git.kernel.org/stable/c/9ddbc95dac167e3f2d0e3859e6ce022ae0184fc1

https://git.kernel.org/stable/c/9652e7e23137538169f60323300cae3413475685

https://git.kernel.org/stable/c/72a5e45f606ec454ef556a68ffd92e06b0677f44

https://git.kernel.org/stable/c/71690d26c1415e816158b45ee354367244c50d4c

https://git.kernel.org/stable/c/2677fc48dd10dc08cdec99c2692d50fe5f48dcbf

https://git.kernel.org/stable/c/20166fd9a4ad15d7eccc63c9dc99680aea6558ef

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.0021