Executive brief
The Linux kernel's ath11k Wi-Fi driver contains a memory leak in the service ready event handler. During TLV parsing, a temporary memory allocation (mac_phy_caps) is freed on success but not when parsing fails, causing memory to be wasted. While this is primarily a resource leak rather than a security vulnerability, repeated triggering could contribute to denial-of-service conditions.
Technical details
This is a memory leak vulnerability (CWE-401) in the ath11k_service_ready_ext_event() function within the Linux kernel's wireless driver. The vulnerability occurs when the svc_rdy_ext.mac_phy_caps structure is allocated during TLV (Type-Length-Value) parsing but is only freed on the success path, not on the error path. If parsing succeeds far enough to allocate mac_phy_caps and then encounters a later TLV parsing error, the allocated memory is never freed. The fix is simple: add a kfree(svc_rdy_ext.mac_phy_caps) call in the error handler before returning. This is a local issue affecting only systems running the affected kernel code path during Wi-Fi driver initialization.
Affected products
- Linux Linux kernel 5.x through 7.x (all versions affected before fix)
Timeline
- 2026-09-17: disclosed: Advisory published
- 2026-07-31: patched: Patch merged upstream