KernelScan.io

HIGH Introduced in 7.0

ath12k MlPeerId OOB

CVE-2026-74554

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() ath12k_mac_dp_peer_cleanup() clears the ML peer ID slot on the free_ml_peer_id_map bitmap by indexing it with dp_peer->peer_id. That is wrong: dp_peer->peer_id for an MLO peer always carries the ATH12K_PEER_ML_ID_VALID bit (BIT(13)), so clear_bit() is invoked with index >= 0x2000, which is far outside the bitmap of ATH12K_MAX_MLO_PEERS (256) bits and corrupts memory adjacent to ah->free_ml_peer_id_map. The intended bitmap entry also never gets cleared, so subsequent ath12k_peer_ml_alloc() calls eventually run out of IDs. The ID without the VALID bit is what ath12k_peer_ml_alloc() returned and is stored in ahsta->ml_peer_id. Use that instead. While there, also reset ahsta->ml_peer_id to ATH12K_MLO_PEER_ID_INVALID so the bitmap and ahsta->ml_peer_id stay in sync. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3

02

Engine v0.6.0

Risk summary

Devices using Qualcomm ath12k WiFi hardware (WCN7850, QCN9274) with Wi-Fi 7 MLO peers connected are vulnerable to kernel memory corruption during peer cleanup on core reset. An attacker within WiFi range can trigger an out-of-bounds write that corrupts adjacent kernel memory and eventually exhausts MLO peer IDs, leading to potential code execution or denial of service.

Affecteddrivers/net/wireless/ath/ath12k/mac.c (ath12k WiFi driver)

Vulnerability analysis

When the WiFi driver cleans up multi-link peers after a hardware reset, it uses an identifier that still contains a hardware flag bit as a table index. This makes the index far larger than the tracking table, so the cleanup writes outside the intended area and corrupts adjacent kernel memory. The correct table entry is also never freed, so repeated connections eventually exhaust all available slots. The fix removes the flag bit before indexing and resets the stored identifier afterward to keep the table consistent. This can be reached on affected Qualcomm WiFi hardware when multi-link peers are present and a hardware reset occurs; an attacker within wireless range can connect as such a peer and wait for or trigger a reset to cause the corruption.

03

BranchIntroducedFixed inPatch commit
7.17.07.1.8234b5cb81e6f
mainline7.07.2-rc647abd2ca2815