HIGH Introduced in 7.0
ath12k MlPeerId OOB
CVE-2026-74554
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.8HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() ath12k_mac_dp_peer_cleanup() clears the ML peer ID slot on the free_ml_peer_id_map bitmap by indexing it with dp_peer->peer_id. That is wrong: dp_peer->peer_id for an MLO peer always carries the ATH12K_PEER_ML_ID_VALID bit (BIT(13)), so clear_bit() is invoked with index >= 0x2000, which is far outside the bitmap of ATH12K_MAX_MLO_PEERS (256) bits and corrupts memory adjacent to ah->free_ml_peer_id_map. The intended bitmap entry also never gets cleared, so subsequent ath12k_peer_ml_alloc() calls eventually run out of IDs. The ID without the VALID bit is what ath12k_peer_ml_alloc() returned and is stored in ahsta->ml_peer_id. Use that instead. While there, also reset ahsta->ml_peer_id to ATH12K_MLO_PEER_ID_INVALID so the bitmap and ahsta->ml_peer_id stay in sync. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3
02KernelScan AI Analysis
Risk summary
Devices using Qualcomm ath12k WiFi hardware (WCN7850, QCN9274) with Wi-Fi 7 MLO peers connected are vulnerable to kernel memory corruption during peer cleanup on core reset. An attacker within WiFi range can trigger an out-of-bounds write that corrupts adjacent kernel memory and eventually exhausts MLO peer IDs, leading to potential code execution or denial of service.
Vulnerability analysis
When the WiFi driver cleans up multi-link peers after a hardware reset, it uses an identifier that still contains a hardware flag bit as a table index. This makes the index far larger than the tracking table, so the cleanup writes outside the intended area and corrupts adjacent kernel memory. The correct table entry is also never freed, so repeated connections eventually exhaust all available slots. The fix removes the flag bit before indexing and resets the stored identifier afterward to keep the table consistent. This can be reached on affected Qualcomm WiFi hardware when multi-link peers are present and a hardware reset occurs; an attacker within wireless range can connect as such a peer and wait for or trigger a reset to cause the corruption.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.1 | 7.0 | 7.1.8 | 234b5cb81e6f |
| mainline | 7.0 | 7.2-rc6 | 47abd2ca2815 |