CVE-2026-92497

high

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread. Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

References

https://git.kernel.org/stable/c/9e6ec0977f0b9c16fc20efea050e3eea8f66e34b

https://git.kernel.org/stable/c/9784faa6afd26693287e8e4569bdedee00212909

https://git.kernel.org/stable/c/95d1bd1db9e9d8eccffc880166e01c4775115716

https://git.kernel.org/stable/c/7698656a2f7b045af5a6859766238cefea1b1945

https://git.kernel.org/stable/c/07659388110de004cbb753f3c7bc85e657e51f7a

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00168