Integer underflow in Linux kernel - CVE-2026-89524
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an integer underflow in ath6kl_cfg80211_connect_event() when handling association events with request or response lengths shorter than their fixed information element offsets. A remote attacker can trigger such an association event to disclose sensitive information.