Junglewise Threat Intelligence

CVE-2026-64155: Linux Kernel ath11k Wi-Fi driver memory leak in WMI WOW calls

CVE-2026-64155 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ath11k Wi-Fi driver that could lead to memory leaks. This occurs when certain wireless management commands fail, causing the system to fail to release allocated memory buffers. Over time, this could potentially impact system stability or performance by exhausting available memory resources.

Technical details

A memory leak vulnerability exists in the Linux kernel ath11k Wi-Fi driver within the 'drivers/net/wireless/ath/ath11k/wmi.c' component. The functions 'ath11k_wmi_wow_host_wakeup_ind' and 'ath11k_wmi_wow_enable' failed to check the return value of 'ath11k_wmi_cmd_send'. Consequently, if the command transmission failed, the associated socket buffer (skb) was not freed in the error path. This flaw allows for a gradual depletion of kernel memory. The issue has been resolved by implementing proper return value checks and ensuring 'dev_kfree_skb' is called upon failure.

Affected products

  • Linux Linux Kernel 5.11 to 6.18.34

Timeline

  • 2026-05-06: disclosed: Initial patch authored
  • 2026-07-19: advisory: CVE published by kernel.org and NVD

References

Related threats