SB20260918227 - Out-of-bounds read in Linux kernel ath ath11k driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-92496)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in ath11k_wmi_tlv_op_rx() when processing a firmware buffer shorter than a WMI command header. A local user can supply a malformed firmware buffer to read out-of-bounds memory.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/20166fd9a4ad15d7eccc63c9dc99680aea6558ef
- https://git.kernel.org/stable/c/2677fc48dd10dc08cdec99c2692d50fe5f48dcbf
- https://git.kernel.org/stable/c/71690d26c1415e816158b45ee354367244c50d4c
- https://git.kernel.org/stable/c/72a5e45f606ec454ef556a68ffd92e06b0677f44
- https://git.kernel.org/stable/c/9652e7e23137538169f60323300cae3413475685
- https://git.kernel.org/stable/c/9ddbc95dac167e3f2d0e3859e6ce022ae0184fc1
- https://git.kernel.org/stable/c/9ef9dd30058cc9223c72f711dca1a28a5947d0c5
- https://git.kernel.org/stable/c/f9726f6d97dca94ab14739c8b632301a940a7e8f