Executive brief
A vulnerability exists in the Linux kernel's Qualcomm Wi-Fi driver (ath12k) that could allow an attacker to cause a system crash or potentially access sensitive memory. The issue occurs during the setup of wireless connections when the system fails to properly clean up internal tracking data. This could lead to operational instability or unauthorized data exposure for devices using affected Qualcomm Wi-Fi hardware.
Technical details
An out-of-bounds (OOB) access vulnerability exists in the ath12k wireless driver within the Linux kernel. The root cause is a failure to decrement the Traffic Identifier (TID) counter during the error handling path of the 'ath12k_dp_rx_peer_frag_setup' function. When a fragmentation setup fails, the stale TID value leads to an out-of-bounds access in the 'peer->rx_tid[]' array during subsequent cleanup operations. This is reachable via adjacent network interaction (Wi-Fi). The vulnerability can result in an out-of-bounds read or write, potentially leading to a kernel panic (DoS) or information disclosure. Patches have been released for various stable kernel branches including 6.6.x, 6.12.x, 6.15.x, and 6.16.x.
Affected products
- Linux Linux Kernel 6.3 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-11: disclosed: Initial publication date
- 2025-06-23: patched: Mainline patch committed
References
- https://git.kernel.org/stable/c/7c0884fcd2ddde0544d2e77f297ae461e1f53f58
- https://git.kernel.org/stable/c/7c3e99fd4a66a5ac9c7dd32db07359666efe0002
- https://git.kernel.org/stable/c/9530d666f4376c294cdf4348c29fe3542fec980a
- https://git.kernel.org/stable/c/a3b73c72c42348bf1555fd2b00f32f941324b242
- https://git.kernel.org/stable/c/eb1e1526b82b8cf31f1ef9ca86a2647fb6cd89c6