๐Ÿ” CVE Alert

CVE-2026-68353

UNKNOWN 0.0

wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bdcd81707973cf8aa9305337166f8ee842a050d4 < 69ac7ba3a3df6654e7daa82674575a8c4a1a63ea bdcd81707973cf8aa9305337166f8ee842a050d4 < 289edc3c71344b89e6522891147cfb8f61b088bb bdcd81707973cf8aa9305337166f8ee842a050d4 < eb636fbc443149b3501c3f97e26225ddcb314a0f bdcd81707973cf8aa9305337166f8ee842a050d4 < c38b0d5c661951b5dd082bdf31f8a57a0ce6e540 bdcd81707973cf8aa9305337166f8ee842a050d4 < 3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495
Linux / Linux
3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea git.kernel.org: https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb git.kernel.org: https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f git.kernel.org: https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540 git.kernel.org: https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495