{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89524","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.719Z","datePublished":"2026-09-11T19:44:05.548Z","dateUpdated":"2026-09-14T12:00:40.689Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:40.689Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets\n\nath6kl_cfg80211_connect_event() subtracts fixed IE offsets from\nassoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower\nbound. The aggregate check recently added to ath6kl_wmi_connect_event_rx()\nbounds the declared lengths from above (their sum must fit the received\nevent), but an assoc request/response shorter than its fixed offset still\nunderflows here: the u8 wraps to ~250, and cfg80211_connect_result() /\ncfg80211_roamed() then treat that wrapped value as the IE length and copy\nthat many bytes out of the small assoc_info buffer to user space via\nnl80211, disclosing adjacent slab memory.\n\nClamp both lengths to their offsets before subtracting.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing lower bound is evident from source. Compile-tested."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - ath6kl is a fullMAC WiFi driver; assoc_req_len/assoc_resp_len come from a WMI_CONNECT_EVENT built from the 802.11 association exchange. A rogue or evil-twin AP, or a frame injector in radio range, supplies a truncated assoc/reassoc response, so the attacker must share the wireless segment.\nAC:L - A malicious AP can send a truncated association or reassociation response so firmware reports assoc_req_len < 4 or assoc_resp_len < 6. The u8 subtraction wraps deterministically and cfg80211 copies the wrapped length; the attacker can force (re)association or roaming with deauth until the event is emitted.\nPR:N - The WMI connect event is handled on the firmware receive path with no capability check, local account, or user-namespace gate. An adjacent attacker needs no privileges on the victim system.\nUI:N - Devices with a saved or open profile auto-associate, and the SME_CONNECTED roam path (cfg80211_roamed) delivers the same underflowed IEs while already connected, so no extra victim action is required.\nS:U - The out-of-bounds read, kernel-memory disclosure, and any resulting oops stay inside the host kernel's security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - After the u8 wrap, cfg80211_connect_result()/cfg80211_roamed() treat ~250-byte lengths as IE sizes and copy that many bytes from the small assoc_info skb into nl80211 CONNECT/ROAM events (and WEXT assoc IE events), disclosing adjacent slab memory far beyond a few bytes.\nI:N - The underflow only inflates the length used for an out-of-bounds read and copy to userspace; no kernel memory is written out of bounds and no attacker-controlled pointer is used to modify kernel state.\nA:H - Copying ~250 bytes past a short WMI skb can walk off the slab object into unmapped or redzoned memory, causing a kernel oops or KASAN panic that an adjacent attacker can retrigger by repeating association."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath6kl/cfg80211.c"],"versions":[{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"225587bdbf4b0eb5265a71ee4dc183561a1857fc","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"d337213a889705a69735079606d0b4c672b17605","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"e11d5ae96d5e52cb48fa27c6ad352d766d0322fb","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"6deb4d7a0c3d91821b2a8d5239e3d9933d9217d9","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"e3619bed5da125713b29ac881dc66f5e06606f88","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"e1330d719c047c4d8190a16be034b29fc601a815","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"8eb73016fb3968cf2db3987a92764563a3af773a","status":"affected","versionType":"git"},{"version":"bdcd81707973cf8aa9305337166f8ee842a050d4","lessThan":"3bbd05723d15dd06f0560bcd94fbf9a91b5f5613","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath6kl/cfg80211.c"],"versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/225587bdbf4b0eb5265a71ee4dc183561a1857fc"},{"url":"https://git.kernel.org/stable/c/d337213a889705a69735079606d0b4c672b17605"},{"url":"https://git.kernel.org/stable/c/e11d5ae96d5e52cb48fa27c6ad352d766d0322fb"},{"url":"https://git.kernel.org/stable/c/6deb4d7a0c3d91821b2a8d5239e3d9933d9217d9"},{"url":"https://git.kernel.org/stable/c/e3619bed5da125713b29ac881dc66f5e06606f88"},{"url":"https://git.kernel.org/stable/c/e1330d719c047c4d8190a16be034b29fc601a815"},{"url":"https://git.kernel.org/stable/c/8eb73016fb3968cf2db3987a92764563a3af773a"},{"url":"https://git.kernel.org/stable/c/3bbd05723d15dd06f0560bcd94fbf9a91b5f5613"}],"title":"wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets","x_generator":{"engine":"bippy-1.2.0"}}}}