8.8

CVE-2026-97442

wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi

In certain cases, hardware might provide packets with a
length greater than the maximum native Wi-Fi header length.
This can lead to accessing and modifying fields in the header
within the ath11k_dp_rx_h_undecap_nwifi() function for the
DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and
potentially result in invalid data access and memory corruption.

Kernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]
Call trace:
 ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]
 ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]
 ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]
 ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]
 ath11k_dp_service_srng+0x2e0/0x348 [ath11k]

Add a sanity check before processing the SKB to prevent invalid
data access in the undecap native Wi-Fi function for the
DP_RX_DECAP_TYPE_NATIVE_WIFI decap type.

This adapted from the discussion/patch of the ath12k driver [1].

Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version acc79d981c1462b22a7a2cb0d39725f8c01fc425
Version < 958cf3696ddc5ccafd3d0b8b0c03d90bcd771c0c
Status affected
Version acc79d981c1462b22a7a2cb0d39725f8c01fc425
Version < b4ef30f1d107aae460edf731a7c2d187fbc46a32
Status affected
Version acc79d981c1462b22a7a2cb0d39725f8c01fc425
Version < 1c0a13be76db3c1cf774aa11d9f4c3f8239ac567
Status affected
Version acc79d981c1462b22a7a2cb0d39725f8c01fc425
Version < 00738665c875ab34efa7126ea63c9d70b48ee169
Status affected
Version acc79d981c1462b22a7a2cb0d39725f8c01fc425
Version < 6b471e9aefee9ed73278eb1141e0d8530a56fae9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.133
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567
https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169
https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9
https://git.kernel.org/stable/c/958cf3696ddc5ccafd3d0b8b0c03d90bcd771c0c
https://git.kernel.org/stable/c/b4ef30f1d107aae460edf731a7c2d187fbc46a32