PT-2026-94747 · Linux · Linux Kernel
CVE-2026-90399
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A stride mismatch exists in the
ath12k wmi mac phy caps parse() function. The kzalloc() function sizes the mac phy caps buffer using a clamped length, but the subsequent memcpy() operation advances the destination using the size of the full structure via C pointer arithmetic. If the firmware sends short Type-Length-Values (TLVs), data is written beyond the allocated buffer boundaries. Additionally, the ath12k pull mac phy cap svc ready ext() function indexes the buffer using full-struct pointer arithmetic, requiring the allocation size to match that stride.Recommendations
Update the Linux kernel to a version where
kzalloc objs() is used in ath12k wmi mac phy caps parse() to ensure consistent allocation size and pointer stride.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel