PT-2026-94746 · Linux · Linux Kernel
CVE-2026-90398
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A stride mismatch exists in the
ath11k wmi tlv mac phy caps parse() function. The kcalloc() function sizes the mac phy caps buffer using a clamped length, but the subsequent memcpy() operation advances the destination using the size of the full structure via C pointer arithmetic. If the firmware sends short Type-Length-Values (TLVs), data is written beyond the allocated buffer boundaries. Additionally, the ath11k pull mac phy cap svc ready ext() function indexes the buffer using full-struct pointer arithmetic, requiring the allocation size to match that stride.Recommendations
Update the Linux kernel to a version where
kzalloc objs() is used in ath11k wmi tlv mac phy caps parse() to ensure consistent allocation size and pointer stride.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel