Executive brief
The Linux kernel's ath12k WiFi driver contains an out-of-bounds read vulnerability in its wireless management interface (WMI) event handler. Malicious or malformed firmware responses could trigger memory reads beyond allocated buffer boundaries, potentially exposing sensitive kernel data or causing a system crash. This affects systems running the ath12k driver for Qualcomm Wi-Fi 7 devices.
Technical details
The vulnerability exists in the ath12k_wmi_process_csa_switch_count_event() function, which processes channel switch announcement (CSA) events from firmware. The num_vdevs field is extracted directly from firmware without validation against the actual TLV (Type-Length-Value) payload size, and no TLV policy entry enforces a minimum length for the event structure. An attacker controlling firmware responses (or an unauthenticated adjacent network attacker in certain scenarios) can craft malformed WMI events where num_vdevs exceeds the available vdev_ids array, causing an out-of-bounds read. The fix adds a TLV policy entry to enforce minimum length validation and bounds-checks num_vdevs against the actual TLV payload length before iterating over the array.
Affected products
- Linux Linux Kernel 6.0 and later (ath12k driver)
Timeline
- 2026-09-17: disclosed: CVE-2026-90408 published
- 2026-07-24: patched: Fix committed upstream (878654eb78c6aa0ff585baf1376567c775ca28ec)
- 2026-09-14: patched: Fix backported to stable kernels