๐Ÿ” CVE Alert

CVE-2026-68353

HIGH 8.1

wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
bdcd81707973cf8aa9305337166f8ee842a050d4 < 5297299c3fa6133275db0be99d69cd759b6cbfe9 bdcd81707973cf8aa9305337166f8ee842a050d4 < 35196a07603f8c94a4943093bc26d5b5826285f8 bdcd81707973cf8aa9305337166f8ee842a050d4 < 0e0fc04af9b443c6b425f00fb604ff599bc80d1d bdcd81707973cf8aa9305337166f8ee842a050d4 < 69ac7ba3a3df6654e7daa82674575a8c4a1a63ea bdcd81707973cf8aa9305337166f8ee842a050d4 < 289edc3c71344b89e6522891147cfb8f61b088bb bdcd81707973cf8aa9305337166f8ee842a050d4 < eb636fbc443149b3501c3f97e26225ddcb314a0f bdcd81707973cf8aa9305337166f8ee842a050d4 < c38b0d5c661951b5dd082bdf31f8a57a0ce6e540 bdcd81707973cf8aa9305337166f8ee842a050d4 < 3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495
Linux / Linux
3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5297299c3fa6133275db0be99d69cd759b6cbfe9 git.kernel.org: https://git.kernel.org/stable/c/35196a07603f8c94a4943093bc26d5b5826285f8 git.kernel.org: https://git.kernel.org/stable/c/0e0fc04af9b443c6b425f00fb604ff599bc80d1d git.kernel.org: https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea git.kernel.org: https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb git.kernel.org: https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f git.kernel.org: https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540 git.kernel.org: https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495