Executive brief
A vulnerability was identified in the Linux kernel's ath5k Wi-Fi driver where the system incorrectly writes data outside of its intended memory boundaries. This occurs during wireless transmission tasks and results in a minor memory overwrite. While the practical impact is considered negligible, it represents a technical flaw in how the driver handles wireless data rates.
Technical details
An array-index-out-of-bounds access exists in the ath5k driver within 'drivers/net/wireless/ath/ath5k/base.c'. The vulnerability occurs in the 'ath5k_tx_frame_completed' function when the driver attempts to set a sentinel value (idx = -1) at an index calculated as 'ts->ts_final_idx + 1'. On certain hardware like the 5212, 'ts_final_idx' can be 3, causing an access at index 4 of an array with a maximum size of 4 (IEEE80211_TX_MAX_RATES). This results in an out-of-bounds write that overwrites the adjacent 'ack_signal' member in the 'info->status' structure. The fix introduces a bounds check to ensure the index is within the array limits before writing.
Affected products
- Linux Linux kernel ath5k driver
Timeline
- 2025-12-09: disclosed: Vulnerability reported and patch authored
- 2026-06-08: advisory: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/568173ad9bd0b46cc6cd937dea8791e9b5eefa57
- https://git.kernel.org/stable/c/744c19e266b0d2628c5951439195dcef27eadacf
- https://git.kernel.org/stable/c/83226c71af53fb9b3cad40cb9a9a79f36d68c020
- https://git.kernel.org/stable/c/9dd6aae4bc7bfa11088d928670a3315eae542769
- https://git.kernel.org/stable/c/d6869537013b1f21b292342752d97868b79b5934
- https://git.kernel.org/stable/c/d748603f12baff112caa3ab7d39f50100f010dbd
- https://git.kernel.org/stable/c/e9f1081bc775146156def0dbc821b92f35d56afb