PT-2026-94747 · Linux · Linux Kernel

CVE-2026-90399

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stride mismatch exists in the ath12k wmi mac phy caps parse() function. The kzalloc() function sizes the mac phy caps buffer using a clamped length, but the subsequent memcpy() operation advances the destination using the size of the full structure via C pointer arithmetic. If the firmware sends short Type-Length-Values (TLVs), data is written beyond the allocated buffer boundaries. Additionally, the ath12k pull mac phy cap svc ready ext() function indexes the buffer using full-struct pointer arithmetic, requiring the allocation size to match that stride.
Recommendations Update the Linux kernel to a version where kzalloc objs() is used in ath12k wmi mac phy caps parse() to ensure consistent allocation size and pointer stride.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102621
CVE-2026-90399
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel