Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68352

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.

A flaw was found in the Linux kernel's ath6kl Wi-Fi driver. The driver does not properly validate the lengths of firmware-controlled information elements (IEs) during a connect event. This vulnerability allows the sum of these lengths to exceed the allocated buffer, resulting in an out-of-bounds read. An attacker could exploit this to cause state corruption within the driver, potentially leading to a denial of service.

Отчет

This issue affects Qualcomm ath6kl Wi-Fi. Firmware-controlled IE lengths in connect events are not validated against buffer size, causing OOB reads. Systems without ath6kl hardware are not affected.

Меры по смягчению последствий

To mitigate this issue, prevent the ath6kl module from loading. See https://access.redhat.com/solutions/41278 for instructions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelWill not fix
Red Hat Enterprise Linux 9kernel-rtWill not fix
Red Hat Enterprise Linux for NVIDIA 26kernelNot affected
Red Hat OpenShift Container Platform 4rhcosWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2513376kernel: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event

EPSS

Процентиль: 35%
0.00419
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.

CVSS3: 8.3
nvd
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.

CVSS3: 7.1
msrc
21 день назад

wifi: ath6kl: fix OOB read from firmware IE lengths in connect event

CVSS3: 8.3
debian
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: w ...

CVSS3: 8.3
github
21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.

EPSS

Процентиль: 35%
0.00419
Низкий

5.5 Medium

CVSS3