KernelScan.io

HIGH Introduced in 3.2

ath6kl TxComplete OOB

CVE-2026-68353

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

KernelScan AI8.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg. Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

02

Engine v0.6.0

Risk summary

The ath6kl WiFi driver trusts a firmware-supplied count field when processing TX completion events, allowing an out-of-bounds read of up to 1020 bytes past the event buffer. An attacker within WiFi range of a device using an affected ath6kl wireless chipset could trigger this by influencing the firmware to emit a malformed completion event. The impact is limited to potential kernel memory disclosure and possible denial of service if the over-read accesses unmapped memory.

Affecteddrivers/net/wireless/ath/ath6kl/wmi.c (ath6kl WMI)

Vulnerability analysis

The ath6kl wireless driver processes events from the WiFi chipset firmware that report completed packet transmissions. The number of completions reported by the firmware is used to iterate over a data buffer, but the driver never verifies that the buffer is actually large enough to hold that many entries. When the firmware sends an inflated completion count, the driver reads past the end of the buffer, exposing up to 1020 bytes of adjacent kernel memory. The fix adds a length check before the loop so that any event whose reported count exceeds the buffer capacity is rejected. This code path is reachable from any device within WiFi range that can trigger transmission activity on the affected ath6kl interface, requiring no authentication or prior privileges.

03

BranchIntroducedFixed inPatch commit
5.103.25.10.2655297299c3fa6
6.13.26.1.1830e0fc04af9b4
6.63.26.6.14869ac7ba3a3df
7.13.27.1.6c38b0d5c6619
6.123.26.12.101289edc3c7134
5.153.25.15.21635196a07603f
mainline3.27.23a21c89215cc
6.183.26.18.42eb636fbc4431