8.4

CVE-2026-90399

wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()

Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The
subsequent memcpy() destination advances by sizeof(full struct) per slot
via C pointer arithmetic, not by the clamped len. When firmware sends
short TLVs, the second and later slots are written past the end of the
allocation.

The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.

Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d889913205cf7ebda905b1e62c5867ed4e39f6c2
Version < d3355e0fdbbf531ca8b82a6a3feb80a1b7306a8b
Status affected
Version d889913205cf7ebda905b1e62c5867ed4e39f6c2
Version < b9a5d12cbdeb860306f8d47c92caee0ea6ee0e0a
Status affected
Version d889913205cf7ebda905b1e62c5867ed4e39f6c2
Version < 26f8f87f0a556e7984366c64cebc16d49e15d22f
Status affected
Version d889913205cf7ebda905b1e62c5867ed4e39f6c2
Version < 4c6eb712a91fa079be6f9f1419c96e0ad2227081
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d3355e0fdbbf531ca8b82a6a3feb80a1b7306a8b
https://git.kernel.org/stable/c/b9a5d12cbdeb860306f8d47c92caee0ea6ee0e0a
https://git.kernel.org/stable/c/26f8f87f0a556e7984366c64cebc16d49e15d22f
https://git.kernel.org/stable/c/4c6eb712a91fa079be6f9f1419c96e0ad2227081