HIGH Introduced in 3.2
ath6kl ConnectEvent OOB
CVE-2026-68352
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
KernelScan AI8.3HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.
02KernelScan AI Analysis
Risk summary
A malicious WiFi access point within radio range can exploit this vulnerability by crafting beacons or association responses with inflated IE length fields. When an affected device connects to the rogue AP, the driver reads past its event buffer, potentially leaking kernel memory and corrupting driver state. Any device using the ath6kl WiFi chipset with WiFi enabled is at risk.
Vulnerability analysis
The ath6kl WiFi driver processes firmware connect events containing length fields for beacon, association request, and association response information elements. These firmware-supplied lengths are trusted without validation, so their combined total can exceed the actual event buffer size. When the driver parses IEs using these unchecked lengths, it reads out of bounds, potentially exposing kernel heap memory and corrupting internal driver state. A malicious access point within WiFi range can trigger this by advertising crafted IE lengths in its beacon or association response frames, which the firmware forwards to the driver. The fix adds a simple bounds check that rejects connect events whose total IE length exceeds the available buffer, returning an error before any parsing occurs.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 3.2 | 5.10.265 | 7cae33e3e09a |
| 5.15 | 3.2 | 5.15.216 | 1eeed9efc9a4 |
| 6.6 | 3.2 | 6.6.148 | 1c690f7c4c5b |
| 6.18 | 3.2 | 6.18.42 | 33b5342d2080 |
| 7.1 | 3.2 | 7.1.6 | 94e1bfcefe82 |
| mainline | 3.2 | 7.2 | 6b47b29730de |
| 6.1 | 3.2 | 6.1.183 | a38d7d6376b2 |
| 6.12 | 3.2 | 6.12.101 | d70c0a850c21 |