wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication

Summary

CVECVE-2026-74340
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:34 UTC
Updated2026-08-15 06:22:34 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication The firmware-controlled rsp->count field is used as the loop bound for indexing into the flexible rsp->regs[] array without validation against the message length. A count exceeding the actual data causes out-of- bounds reads from the heap-allocated message buffer. Add a check that count fits within the received message.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba 22b0b8572a64362531dd0ed499b75e16282aeb2b git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba 3cf92b44c4fb88a5e8de8733a4494c0956606bca git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba 0907c06dccae9e3c8d5a68eb9014beec73a36e79 git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba 64228dfc4247aca178c01e5a37af7d8dcc7a6089 git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba 23d210877968657bd07e1a517e0b516db20a1d80 git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba f03782f7f41f2afee5076a1ef08ced5649218771 git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba f987efff29a5fe45320ea5991c9d5cb98b676953 git Not specified
CNA Linux Linux affected 43efa3c0f241e04862be8e6a68ff765d36cde1ba df2187acfca6c6cca372c5d35f42394d9c270b09 git Not specified
CNA Linux Linux affected 4.11 Not specified
CNA Linux Linux unaffected 4.11 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/64228dfc4247aca178c01e5a37af7d8dcc7a6089 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/22b0b8572a64362531dd0ed499b75e16282aeb2b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f987efff29a5fe45320ea5991c9d5cb98b676953 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/df2187acfca6c6cca372c5d35f42394d9c270b09 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f03782f7f41f2afee5076a1ef08ced5649218771 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0907c06dccae9e3c8d5a68eb9014beec73a36e79 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3cf92b44c4fb88a5e8de8733a4494c0956606bca 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/23d210877968657bd07e1a517e0b516db20a1d80 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report