CVE-2026-92497

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()

Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread.

Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd889913205cf7ebda905b1e62c5867ed4e39f6c2 < 9784faa6afd26693287e8e4569bdedee00212909affected
LinuxLinuxd889913205cf7ebda905b1e62c5867ed4e39f6c2 < 07659388110de004cbb753f3c7bc85e657e51f7aaffected
LinuxLinuxd889913205cf7ebda905b1e62c5867ed4e39f6c2 < 95d1bd1db9e9d8eccffc880166e01c4775115716affected
LinuxLinuxd889913205cf7ebda905b1e62c5867ed4e39f6c2 < 9e6ec0977f0b9c16fc20efea050e3eea8f66e34baffected
LinuxLinuxd889913205cf7ebda905b1e62c5867ed4e39f6c2 < 7698656a2f7b045af5a6859766238cefea1b1945affected
LinuxLinux6.3affected
LinuxLinux0 < 6.3unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References