{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97442","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.870Z","datePublished":"2026-09-24T16:03:56.458Z","dateUpdated":"2026-10-03T10:58:27.589Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:27.589Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi\n\nIn certain cases, hardware might provide packets with a\nlength greater than the maximum native Wi-Fi header length.\nThis can lead to accessing and modifying fields in the header\nwithin the ath11k_dp_rx_h_undecap_nwifi() function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type and\npotentially result in invalid data access and memory corruption.\n\nKernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k]\nCall trace:\n ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k]\n ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k]\n ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k]\n ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k]\n ath11k_dp_service_srng+0x2e0/0x348 [ath11k]\n\nAdd a sanity check before processing the SKB to prevent invalid\ndata access in the undecap native Wi-Fi function for the\nDP_RX_DECAP_TYPE_NATIVE_WIFI decap type.\n\nThis adapted from the discussion/patch of the ath12k driver [1].\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The attacker-controlled bytes are the 802.11 frame_control of a native-WiFi MSDU that reaches ath11k_dp_rx_h_undecap_nwifi() via ath11k_pcic_ext_grp_napi_poll/ath11k_ahb_ext_grp_napi_poll → ath11k_dp_service_srng → ath11k_dp_rx_process_wbm_err → ath11k_dp_rx_wbm_err → ath11k_dp_rx_h_mpdu → ath11k_dp_rx_h_undecap. That is over-the-air WiFi, not a routable IP protocol.\nAC:L - ieee80211_hdrlen() is a function of frame_control bits the attacker sets. A 4-address QoS data A-MSDU gives hdr_len 32 (36 with Order), which exceeds decap_hdr[DP_MAX_NWIFI_HDR_LEN] (30). ath11k_frame_mode defaults to ATH11K_HW_TXRX_NATIVE_WIFI, and the attacker retransmits until a non-first subframe takes memcpy(decap_hdr, hdr, hdr_len). No uninfluenced device state.\nPR:N - ath11k_dp_rx_h_null_q_desc() handles WBM DESC_ADDR_ZERO MSDUs with no REO peer/TID queue and still calls ath11k_dp_rx_h_mpdu(); a peer miss falls back to the RX-descriptor encrypt type. That NAPI path has no uid or capability check, so an unauthenticated nearby transmitter whose frame passes the hardware RA filter is enough.\nUI:N - Once the ath11k netdev is up, the injected native-WiFi MSDU is processed in NAPI by ath11k_dp_rx_wbm_err or ath11k_dp_rx_process_msdu. No mount, click, pairing, or other victim action is required at trigger time.\nS:U - The overflow is the 30-byte decap_hdr stack array inside ath11k_dp_rx_h_undecap_nwifi() in the host kernel. It does not escape a VM, bypass the IOMMU, or otherwise leave this security authority.\nC:H - After the overflow, memcpy(skb_push(msdu, hdr_len), decap_hdr, hdr_len) copies the extra 2–6 bytes plus adjacent kernel stack into the skb that ath11k_dp_rx_deliver_msdu() hands to ieee80211_rx_napi, which may forward it in AP/mesh mode — a stack-disclosure primitive.\nI:H - In the !is_first_msdu branch, memcpy(decap_hdr, hdr, hdr_len) writes up to 6 attacker-chosen 802.11 header bytes past the 30-byte stack buffer, overwriting adjacent locals, the stack canary, or saved registers — a controlled OOB write and control-flow hijack primitive.\nA:H - The smash is observed as \"Kernel stack is corrupted in: ath11k_dp_rx_h_undecap\" on the WBM path (ath11k_dp_rx_process_wbm_err → ath11k_dp_rx_h_mpdu). That trips __stack_chk_fail or FORTIFY_SOURCE, and skb_pull(hdr_len) on a short MSDU hits skb_under_panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"versions":[{"version":"acc79d981c1462b22a7a2cb0d39725f8c01fc425","lessThan":"958cf3696ddc5ccafd3d0b8b0c03d90bcd771c0c","status":"affected","versionType":"git"},{"version":"acc79d981c1462b22a7a2cb0d39725f8c01fc425","lessThan":"b4ef30f1d107aae460edf731a7c2d187fbc46a32","status":"affected","versionType":"git"},{"version":"acc79d981c1462b22a7a2cb0d39725f8c01fc425","lessThan":"1c0a13be76db3c1cf774aa11d9f4c3f8239ac567","status":"affected","versionType":"git"},{"version":"acc79d981c1462b22a7a2cb0d39725f8c01fc425","lessThan":"00738665c875ab34efa7126ea63c9d70b48ee169","status":"affected","versionType":"git"},{"version":"acc79d981c1462b22a7a2cb0d39725f8c01fc425","lessThan":"6b471e9aefee9ed73278eb1141e0d8530a56fae9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/ath11k/dp_rx.c"],"versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/958cf3696ddc5ccafd3d0b8b0c03d90bcd771c0c"},{"url":"https://git.kernel.org/stable/c/b4ef30f1d107aae460edf731a7c2d187fbc46a32"},{"url":"https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567"},{"url":"https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169"},{"url":"https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9"}],"title":"wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi","x_generator":{"engine":"bippy-1.2.0"}}}}