In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx
For the reasons also described in commit b383e8abed41 ("wifi: ath9k: avoid
uninit memory read in ath9k_htc_rx_msg()"), ath9k_htc_rx_msg() should
validate pkt_len before accessing the SKB.
For example, the obtained SKB may have been badly constructed with
pkt_len = 8. In this case, the SKB can only contain a valid htc_frame_hdr
but after being processed in ath9k_htc_rx_msg() and passed to
ath9k_wmi_ctrl_rx() endpoint RX handler, it is expected to have a WMI
command header which should be located inside its data payload.
Implement sanity checking inside ath9k_wmi_ctrl_rx(). Otherwise, uninit
memory can be referenced.
Tested on Qualcomm Atheros Communications AR9271 802.11n .
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| Linux | Linux | < 2.6.35 |
| Linux | Linux | < 28259ce4f1f1f9ab37fa817756c89098 |
| Linux | Linux | ≥ 6.4.4, ≤ 6.4.* |
| Linux | Linux | < 90e3c10177573b8662ac9858abd9bf73 |
| Linux | Linux | ≥ 6.5, ≤ * |
| Linux | Linux | < 250efb4d3f5b32a115ea6bf25437ba44 |
| Linux | Linux | ≥ 4.14.322, ≤ 4.14.* |
| Linux | Linux | < ad5425e70789c29b93acafb5bb4629e4 |
| Linux | Linux | ≥ 4.19.291, ≤ 4.19.* |
| Linux | Linux | < d1c2ff2bd84c3692c9df267a2b991ce9 |
| Linux | Linux | ≥ 5.4.251, ≤ 5.4.* |
| Linux | Linux | < 8ed572e52714593b209e3aa352406aff |
| Linux | Linux | ≥ 5.10.188, ≤ 5.10.* |
| Linux | Linux | < 75acec91aeaa07375cd5f418069e61b1 |
| Linux | Linux | ≥ 5.15.121, ≤ 5.15.* |
| Linux | Linux | < f24292e827088bba8de7158501ac25a5 |
| Linux | Linux | ≥ 6.1.39, ≤ 6.1.* |
| Linux | Linux | ≥ 6.3.13, ≤ 6.3.* |
| Linux | Linux | < 0bc12e41af4e3ae1f0efecc377f05144 |
| Linux | Linux | 2.6.35 |
Published: 2025-12-30