wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()
Summary
| CVE | CVE-2026-92497 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:52 UTC |
| Updated | 2026-09-17 17:17:52 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread. Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.064560000 (date 2026-09-18)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 9784faa6afd26693287e8e4569bdedee00212909 git | Not specified |
| CNA | Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 07659388110de004cbb753f3c7bc85e657e51f7a git | Not specified |
| CNA | Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 95d1bd1db9e9d8eccffc880166e01c4775115716 git | Not specified |
| CNA | Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 9e6ec0977f0b9c16fc20efea050e3eea8f66e34b git | Not specified |
| CNA | Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 7698656a2f7b045af5a6859766238cefea1b1945 git | Not specified |
| CNA | Linux | Linux | affected 6.3 | Not specified |
| CNA | Linux | Linux | unaffected 6.3 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/07659388110de004cbb753f3c7bc85e657e51f7a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7698656a2f7b045af5a6859766238cefea1b1945 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9e6ec0977f0b9c16fc20efea050e3eea8f66e34b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/95d1bd1db9e9d8eccffc880166e01c4775115716 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9784faa6afd26693287e8e4569bdedee00212909 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.