PT-2026-105009 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix invalid data access in ath11k dp rx h undecap nwifi
In certain cases, hardware might provide packets with a
length greater than the maximum native Wi-Fi header length.
This can lead to accessing and modifying fields in the header
within the ath11k dp rx h undecap nwifi() function for the
DP RX DECAP TYPE NATIVE WIFI decap type and
potentially result in invalid data access and memory corruption.
Kernel stack is corrupted in: ath11k dp rx h undecap+0x6b0/0x6b0 [ath11k]
Call trace:
ath11k dp rx h mpdu+0x0/0x2e8 [ath11k]
ath11k dp rx h mpdu+0x1e0/0x2e8 [ath11k]
ath11k dp rx wbm err+0x1e0/0x450 [ath11k]
ath11k dp rx process wbm err+0x2fc/0x460 [ath11k]
ath11k dp service srng+0x2e0/0x348 [ath11k]
Add a sanity check before processing the SKB to prevent invalid
data access in the undecap native Wi-Fi function for the
DP RX DECAP TYPE NATIVE WIFI decap type.
This adapted from the discussion/patch of the ath12k driver [1].
Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL V1 V2 SILICONZ IOE-1
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel