KernelScan.io

HIGH Introduced in 3.2

ath6kl AddBaReq OOB

CVE-2026-68199

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA window size aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to compute a kzalloc size and stored in rxtid->hold_q_sz, leading to zero-size or overflowed allocations and subsequent out-of-bounds access. Clean up any previously active aggregation session for the TID first, then return early when win_sz is out of the valid range, instead of proceeding with a broken allocation size.

02

Engine v0.6.0

Risk summary

A device using the ath6kl WiFi driver can be attacked by a nearby unauthenticated attacker sending crafted WiFi frames. The firmware may report an out-of-range aggregation window size that the driver fails to reject, leading to a zero-size or overflowed heap allocation and subsequent out-of-bounds memory access. This can result in kernel memory corruption, information disclosure, or a system crash.

Affecteddrivers/net/wireless/ath/ath6kl/txrx.c (ath6kl WiFi driver)

Vulnerability analysis

The ath6kl WiFi driver accepts a window-size value from the firmware during receive aggregation setup. If the firmware supplies a value outside the allowed range, the driver logs a warning but still uses it to calculate how much memory to allocate. That calculation can wrap around or request zero bytes, producing a buffer that is too small. The driver then accesses memory beyond that buffer during normal packet reception. The corrected code now discards the invalid value and aborts the setup after cleaning up any earlier aggregation state, instead of continuing with the bad allocation. A nearby attacker can trigger this by sending WiFi frames that cause the firmware to pass a malformed window size to the driver; no authentication, special privileges, or user action are needed.

03

BranchIntroducedFixed inPatch commit
6.13.26.1.18367bc9af4f41f
6.123.26.12.1015a65fd472241
6.183.26.18.4258c6c8dc2e02
mainline3.27.244126b6994ee
5.103.25.10.265c8e3ca7954d8
7.13.27.1.6cec0a487cf38
6.63.26.6.148d4558c140782
5.153.25.15.216f480d9910fcf