Back

HIGH

wifi: ath6kl: fix OOB read from firmware IE lengths in connect event

Published Aug 10, 2026

Description

The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled.

Add a check that the total IE length fits within the buffer.

Affected products

Remediation

Red Hat statement

This issue affects Qualcomm ath6kl Wi-Fi. Firmware-controlled IE lengths in connect events are not validated against buffer size, causing OOB reads. Systems without ath6kl hardware are not affected.

Red Hat mitigation

To mitigate this issue, prevent the ath6kl module from loading. See https://access.redhat.com/solutions/41278 for instructions.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 10, 2026
Updated Aug 19, 2026
Reserved Jul 30, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Aug 19, 2026

Red Hat

Severity Moderate
Public date Aug 10, 2026
Bugzilla 2513376

ENISA EUVD

Assigner Linux
Published Aug 10, 2026
Updated Aug 19, 2026

GitHub

No data