SB20260918212 - Out-of-bounds read in Linux kernel ath ath12k driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-92497)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause an out-of-bounds read.
The vulnerability exists due to improper bounds checking in ath12k_wmi_op_rx() when processing a firmware buffer that is shorter than a WMI command header. A local privileged user can cause the function to access header data in an undersized firmware buffer to cause an out-of-bounds read.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07659388110de004cbb753f3c7bc85e657e51f7a
- https://git.kernel.org/stable/c/7698656a2f7b045af5a6859766238cefea1b1945
- https://git.kernel.org/stable/c/95d1bd1db9e9d8eccffc880166e01c4775115716
- https://git.kernel.org/stable/c/9784faa6afd26693287e8e4569bdedee00212909
- https://git.kernel.org/stable/c/9e6ec0977f0b9c16fc20efea050e3eea8f66e34b