{"api_version":"1","generated_at":"2026-09-25T09:24:40+00:00","cve":"CVE-2026-97442","urls":{"html":"https://cve.report/CVE-2026-97442","api":"https://cve.report/api/cve/CVE-2026-97442.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97442","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97442"},"summary":{"title":"wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi\n\nIn certain cases, hardware might provide packets with a\nlength greater than the maximum native Wi-Fi header length.\nThis can lead to accessing and modifying fields in the header\nwithin the ath11k_dp_rx_h_undecap_nwifi() function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type and\npotentially result in invalid data access and memory corruption.\n\nKernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]\nCall trace:\n ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]\n ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]\n ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]\n ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]\n ath11k_dp_service_srng+0x2e0/0x348 [ath11k]\n\nAdd a sanity check before processing the SKB to prevent invalid\ndata access in the undecap native Wi-Fi function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type.\n\nThis adapted from the discussion/patch of the ath12k driver [1].\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:22","updated_at":"2026-09-25 05:17:05"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567","name":"https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169","name":"https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9","name":"https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97442","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97442","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 1c0a13be76db3c1cf774aa11d9f4c3f8239ac567 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 00738665c875ab34efa7126ea63c9d70b48ee169 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 6b471e9aefee9ed73278eb1141e0d8530a56fae9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.111 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.53 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"1c0a13be76db3c1cf774aa11d9f4c3f8239ac567","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"00738665c875ab34efa7126ea63c9d70b48ee169","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6b471e9aefee9ed73278eb1141e0d8530a56fae9","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6.12.111","status":"affected","version":"0","versionType":"semver"},{"lessThan":"6.18.53","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi\n\nIn certain cases, hardware might provide packets with a\nlength greater than the maximum native Wi-Fi header length.\nThis can lead to accessing and modifying fields in the header\nwithin the ath11k_dp_rx_h_undecap_nwifi() function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type and\npotentially result in invalid data access and memory corruption.\n\nKernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]\nCall trace:\n ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]\n ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]\n ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]\n ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]\n ath11k_dp_service_srng+0x2e0/0x348 [ath11k]\n\nAdd a sanity check before processing the SKB to prevent invalid\ndata access in the undecap native Wi-Fi function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type.\n\nThis adapted from the discussion/patch of the ath12k driver [1].\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1"}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:A - The attacker-controlled bytes are the 802.11 frame_control of a native-WiFi MSDU that reaches ath11k_dp_rx_h_undecap_nwifi() via ath11k_pcic_ext_grp_napi_poll/ath11k_ahb_ext_grp_napi_poll → ath11k_dp_service_srng → ath11k_dp_rx_process_wbm_err → ath11k_dp_rx_wbm_err → ath11k_dp_rx_h_mpdu → ath11k_dp_rx_h_undecap. That is over-the-air WiFi, not a routable IP protocol.\nAC:L - ieee80211_hdrlen() is a function of frame_control bits the attacker sets. A 4-address QoS data A-MSDU gives hdr_len 32 (36 with Order), which exceeds decap_hdr[DP_MAX_NWIFI_HDR_LEN] (30). ath11k_frame_mode defaults to ATH11K_HW_TXRX_NATIVE_WIFI, and the attacker retransmits until a non-first subframe takes memcpy(decap_hdr, hdr, hdr_len). No uninfluenced device state.\nPR:N - ath11k_dp_rx_h_null_q_desc() handles WBM DESC_ADDR_ZERO MSDUs with no REO peer/TID queue and still calls ath11k_dp_rx_h_mpdu(); a peer miss falls back to the RX-descriptor encrypt type. That NAPI path has no uid or capability check, so an unauthenticated nearby transmitter whose frame passes the hardware RA filter is enough.\nUI:N - Once the ath11k netdev is up, the injected native-WiFi MSDU is processed in NAPI by ath11k_dp_rx_wbm_err or ath11k_dp_rx_process_msdu. No mount, click, pairing, or other victim action is required at trigger time.\nS:U - The overflow is the 30-byte decap_hdr stack array inside ath11k_dp_rx_h_undecap_nwifi() in the host kernel. It does not escape a VM, bypass the IOMMU, or otherwise leave this security authority.\nC:H - After the overflow, memcpy(skb_push(msdu, hdr_len), decap_hdr, hdr_len) copies the extra 2–6 bytes plus adjacent kernel stack into the skb that ath11k_dp_rx_deliver_msdu() hands to ieee80211_rx_napi, which may forward it in AP/mesh mode — a stack-disclosure primitive.\nI:H - In the !is_first_msdu branch, memcpy(decap_hdr, hdr, hdr_len) writes up to 6 attacker-chosen 802.11 header bytes past the 30-byte stack buffer, overwriting adjacent locals, the stack canary, or saved registers — a controlled OOB write and control-flow hijack primitive.\nA:H - The smash is observed as \"Kernel stack is corrupted in: ath11k_dp_rx_h_undecap\" on the WBM path (ath11k_dp_rx_process_wbm_err → ath11k_dp_rx_h_mpdu). That trips __stack_chk_fail or FORTIFY_SOURCE, and skb_pull(hdr_len) on a short MSDU hits skb_under_panic."}]}],"providerMetadata":{"dateUpdated":"2026-09-25T05:10:37.697Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567"},{"url":"https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169"},{"url":"https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9"}],"title":"wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97442","datePublished":"2026-09-24T16:03:56.458Z","dateReserved":"2026-09-24T14:53:16.870Z","dateUpdated":"2026-09-25T05:10:37.697Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:22","lastModifiedDate":"2026-09-25 05:17:05","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97442","Ordinal":"1","Title":"wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_","CVE":"CVE-2026-97442","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97442","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi\n\nIn certain cases, hardware might provide packets with a\nlength greater than the maximum native Wi-Fi header length.\nThis can lead to accessing and modifying fields in the header\nwithin the ath11k_dp_rx_h_undecap_nwifi() function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type and\npotentially result in invalid data access and memory corruption.\n\nKernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]\nCall trace:\n ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]\n ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]\n ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]\n ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]\n ath11k_dp_service_srng+0x2e0/0x348 [ath11k]\n\nAdd a sanity check before processing the SKB to prevent invalid\ndata access in the undecap native Wi-Fi function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type.\n\nThis adapted from the discussion/patch of the ath12k driver [1].\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1","Type":"Description","Title":"wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_"}]}}}