Executive brief
The wcn36xx WiFi driver in the Linux kernel contains an out-of-bounds memory read vulnerability in handling firmware diagnostic messages. A malicious or compromised firmware could craft a message with an invalid count field, causing the driver to read past the end of the allocated message buffer. This could leak sensitive kernel memory or cause a system crash.
Technical details
The vulnerability is a heap-based out-of-bounds read in the wcn36xx driver's PRINT_REG_INFO indication handler (drivers/net/wireless/ath/wcn36xx/smd.c). The firmware-controlled rsp->count field is used directly as a loop bound to index the rsp->regs[] flexible array without validation against the received message length. An attacker who can control firmware (via device compromise or supply-chain attack) can supply a count value exceeding the actual array bounds, causing reads from heap memory beyond the message buffer. The fix adds a bounds check to ensure the count fits within the received message length before processing. The vulnerability was patched on 2026-04-21 by Tristan Madani and requires network-adjacent or local access (firmware control).
Affected products
- Linux Linux kernel Affected versions in 4.x, 5.x, 6.x series; patched with commit df2187acfca6c6cca372c5d35f42394d9c270b09
Timeline
- 2026-08-15: disclosed: Published to NVD
- 2026-04-21: patched: Fix submitted by Tristan Madani