KernelScan.io

HIGH Introduced in 5.6

ath11k RxMsduList Underflow

CVE-2026-68355

CVSS 8.8 / 10.0 KernelScan AI

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() When the first entry in msdu_details has a zero buffer address, the code accesses msdu_details[i - 1] with i == 0, causing a buffer underflow. Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding a separate check for i == 0 before the main condition to prevent the out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.

02

Engine v0.6.0

Risk summary

A device using a Qualcomm ath11k WiFi adapter can be attacked by anyone within WiFi range sending crafted wireless frames. The out-of-bounds read can expose sensitive kernel memory and corrupt internal state, potentially leading to arbitrary code execution or a kernel panic. No privileges on the target device are required.

Affecteddrivers/net/wireless/ath/ath11k/dp_rx.c (ath11k WiFi driver)

Vulnerability analysis

When the ath11k WiFi driver processes a list of received packet descriptors, it checks each entry for a zero buffer address and, upon finding one, reads metadata from the previous entry. If the very first entry has a zero address, the code reads from before the start of the descriptor array, accessing out-of-bounds memory. The fix adds an early check that stops processing when the first entry has a zero buffer address, preventing the underflow. This vulnerability is reachable by an attacker within WiFi range of a device equipped with a Qualcomm ath11k WiFi adapter; no privileges or user interaction on the target are required.

03

BranchIntroducedFixed inPatch commit
5.105.65.10.265085a5fde5bac
5.155.65.15.21631ea4b175bc3
6.15.66.1.18320d18a5ec6ec
6.65.66.6.14869a6a4f60b2d
6.185.66.18.42a154ca3c441a
7.15.67.1.6725c1c3a8c5d
mainline5.67.27f11e7062965
6.125.66.12.101904367381a92