SB20260216127 - Buffer overflow in Linux kernel ath ath10k driver
Published: February 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2026-23133)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the _ath10k_ce_free_pipe() and _ath10k_ce_free_pipe_64() functions in drivers/net/wireless/ath/ath10k/ce.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07f363f305793baecad41816f73056252f3df61e
- https://git.kernel.org/stable/c/1928851334ecfd6e0d663121ab69ac639d4217a6
- https://git.kernel.org/stable/c/5d6fa4d2c9799c09389588da5118a72d97d87e92
- https://git.kernel.org/stable/c/9282a1e171ad8d2205067e8ec3bbe4e3cef4f29f
- https://git.kernel.org/stable/c/b0ad924332a96550a84b8c0ae5483e7042d65fa9
- https://git.kernel.org/stable/c/e2dda298ef809aa201ea7c0904c4d064f6c497cb
- https://git.kernel.org/stable/c/fc8da65f9fe1bc6802f8240b342cfff4f5c7e841