Out-of-bounds read in Linux kernel - CVE-2026-92497
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause an out-of-bounds read.
The vulnerability exists due to improper bounds checking in ath12k_wmi_op_rx() when processing a firmware buffer that is shorter than a WMI command header. A local privileged user can cause the function to access header data in an undersized firmware buffer to cause an out-of-bounds read.
Affected software
How to mitigate CVE-2026-92497
External References
- https://git.kernel.org/stable/c/07659388110de004cbb753f3c7bc85e657e51f7a
- https://git.kernel.org/stable/c/7698656a2f7b045af5a6859766238cefea1b1945
- https://git.kernel.org/stable/c/95d1bd1db9e9d8eccffc880166e01c4775115716
- https://git.kernel.org/stable/c/9784faa6afd26693287e8e4569bdedee00212909
- https://git.kernel.org/stable/c/9e6ec0977f0b9c16fc20efea050e3eea8f66e34b