Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68353

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

A flaw was found in the Linux kernel's ath6kl Wi-Fi driver. The ath6kl_wmi_tx_complete_event_rx() function, responsible for handling Wi-Fi messages, does not properly validate the num_msg field provided by the firmware against the buffer length. A malicious or compromised firmware could send an inflated num_msg value, leading to an out-of-bounds read of up to 1020 bytes past the allocated buffer. This could result in information disclosure or potentially a denial of service.

Отчет

This issue affects Qualcomm ath6kl Wi-Fi. TX complete handler loops on firmware num_msg without buffer bounds check, allowing large OOB reads. Systems without ath6kl hardware are not affected.

Меры по смягчению последствий

To mitigate this issue, prevent the ath6kl module from loading. See https://access.redhat.com/solutions/41278 for instructions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelWill not fix
Red Hat Enterprise Linux 9kernel-rtNot affected
Red Hat Enterprise Linux for NVIDIA 26kernelNot affected
Red Hat OpenShift Container Platform 4rhcosWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2513367kernel: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler

EPSS

Процентиль: 21%
0.0029
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

CVSS3: 8.1
nvd
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

CVSS3: 7.1
msrc
21 день назад

wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler

CVSS3: 8.1
debian
22 дня назад

In the Linux kernel, the following vulnerability has been resolved: w ...

CVSS3: 8.1
github
21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

EPSS

Процентиль: 21%
0.0029
Низкий

5.5 Medium

CVSS3