CVE-2026-92497 PUBLISHED

wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()

Assigner: Linux
Reserved: 16.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()

Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread.

Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d889913205cf7ebda905b1e62c5867ed4e39f6c2 to 9784faa6afd26693287e8e4569bdedee00212909 (excl.)
  • affected from d889913205cf7ebda905b1e62c5867ed4e39f6c2 to 07659388110de004cbb753f3c7bc85e657e51f7a (excl.)
  • affected from d889913205cf7ebda905b1e62c5867ed4e39f6c2 to 95d1bd1db9e9d8eccffc880166e01c4775115716 (excl.)
  • affected from d889913205cf7ebda905b1e62c5867ed4e39f6c2 to 9e6ec0977f0b9c16fc20efea050e3eea8f66e34b (excl.)
  • affected from d889913205cf7ebda905b1e62c5867ed4e39f6c2 to 7698656a2f7b045af5a6859766238cefea1b1945 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.3 is affected
  • unaffected from 0 to 6.3 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References