CVE-2026-89524

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets

ath6kl_cfg80211_connect_event() subtracts fixed IE offsets from assoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower bound. The aggregate check recently added to ath6kl_wmi_connect_event_rx() bounds the declared lengths from above (their sum must fit the received event), but an assoc request/response shorter than its fixed offset still underflows here: the u8 wraps to ~250, and cfg80211_connect_result() / cfg80211_roamed() then treat that wrapped value as the IE length and copy that many bytes out of the small assoc_info buffer to user space via nl80211, disclosing adjacent slab memory.

Clamp both lengths to their offsets before subtracting.

Found by 0sec (https://0sec.ai) using automated source analysis; the missing lower bound is evident from source. Compile-tested.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbdcd81707973cf8aa9305337166f8ee842a050d4 < e3619bed5da125713b29ac881dc66f5e06606f88affected
LinuxLinuxbdcd81707973cf8aa9305337166f8ee842a050d4 < e1330d719c047c4d8190a16be034b29fc601a815affected
LinuxLinuxbdcd81707973cf8aa9305337166f8ee842a050d4 < 8eb73016fb3968cf2db3987a92764563a3af773aaffected
LinuxLinuxbdcd81707973cf8aa9305337166f8ee842a050d4 < 3bbd05723d15dd06f0560bcd94fbf9a91b5f5613affected
LinuxLinux3.2affected
LinuxLinux0 < 3.2unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References