PT-2026-94746 · Linux · Linux Kernel

CVE-2026-90398

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stride mismatch exists in the ath11k wmi tlv mac phy caps parse() function. The kcalloc() function sizes the mac phy caps buffer using a clamped length, but the subsequent memcpy() operation advances the destination using the size of the full structure via C pointer arithmetic. If the firmware sends short Type-Length-Values (TLVs), data is written beyond the allocated buffer boundaries. Additionally, the ath11k pull mac phy cap svc ready ext() function indexes the buffer using full-struct pointer arithmetic, requiring the allocation size to match that stride.
Recommendations Update the Linux kernel to a version where kzalloc objs() is used in ath11k wmi tlv mac phy caps parse() to ensure consistent allocation size and pointer stride.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101936
CVE-2026-90398
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel