Junglewise Threat Intelligence

CVE-2026-74408: Linux kernel ath9k out-of-bounds array access in tx status handling

CVE-2026-74408 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ath9k WiFi driver contains a buffer overflow vulnerability in its wireless packet transmission handler. When the driver receives malformed firmware status information, it can attempt to access memory outside the bounds of an internal queue array, potentially causing system instability, kernel crashes, or code execution with kernel privileges on affected systems.

Technical details

The vulnerability is an out-of-bounds (OOB) array access in the ath_tx_edma_tasklet() function within drivers/net/wireless/ath/ath9k/xmit.c. The function processes a 4-bit hardware field (ts.qid, valid range 0–15) as a direct array index into sc->tx.txq[], which only has 10 entries (ATH9K_NUM_TX_QUEUES). When ts.qid >= 10, an out-of-bounds memory access occurs. No special authentication or user interaction is required; exploitation is possible when a system receives malicious or malformed firmware status responses from the wireless hardware. The fix adds a bounds check before array access, skipping processing of invalid queue IDs. Patches are available upstream and in stable kernel branches.

Affected products

  • Linux Linux kernel Linux 5.0 through 6.x (exact range varies by stable branch; affects all kernel versions containing the ath9k EDMA tx code)

Timeline

  • 2026-08-15: disclosed: CVE-2026-74408 published
  • 2026-07-24: patched: Fix committed to stable kernel trees by Greg Kroah-Hartman

References

Related threats