wifi: ath6kl: fix OOB access from firmware ADDBA window size
Summary
| CVE | CVE-2026-68199 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:07 UTC |
| Updated | 2026-08-10 13:20:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: ath6kl: fix OOB access from firmware ADDBA window size
aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied
win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not
return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to
compute a kzalloc size and stored in rxtid->hold_q_sz, leading to
zero-size or overflowed allocations and subsequent out-of-bounds access.
Clean up any previously active aggregation session for the TID first,
then return early when win_sz is out of the valid range, instead of
proceeding with a broken allocation size. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected bdcd81707973cf8aa9305337166f8ee842a050d4 d4558c140782180e2c80a7588a4af9f8675adfc4 git |
Not specified |
| CNA |
Linux |
Linux |
affected bdcd81707973cf8aa9305337166f8ee842a050d4 5a65fd4722416061698b0a3277222381efbc4882 git |
Not specified |
| CNA |
Linux |
Linux |
affected bdcd81707973cf8aa9305337166f8ee842a050d4 58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c git |
Not specified |
| CNA |
Linux |
Linux |
affected bdcd81707973cf8aa9305337166f8ee842a050d4 cec0a487cf38ac1f9bca240ffe8a94c5014b72f2 git |
Not specified |
| CNA |
Linux |
Linux |
affected bdcd81707973cf8aa9305337166f8ee842a050d4 44126b6994eeb28f2103b638e698f40a1244f327 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.2 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.2 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/44126b6994eeb28f2103b638e698f40a1244f327 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/cec0a487cf38ac1f9bca240ffe8a94c5014b72f2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d4558c140782180e2c80a7588a4af9f8675adfc4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5a65fd4722416061698b0a3277222381efbc4882 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.