CVE-2026-68352

Source
https://cve.org/CVERecord?id=CVE-2026-68352
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68352.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68352
Downstream
Published
2026-08-10T12:03:29Z
Modified
2026-08-21T03:30:12Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H CVSS Calculator
Summary
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: fix OOB read from firmware IE lengths in connect event

The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled.

Add a check that the total IE length fits within the buffer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68352.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bdcd81707973cf8aa9305337166f8ee842a050d4
Fixed
7cae33e3e09a080db96e3a8980c2c8d288318320
Fixed
1eeed9efc9a40e0635e910c37fee86543041b4e1
Fixed
a38d7d6376b295245b53bc98b7ca682c027abaf7
Fixed
1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e
Fixed
d70c0a850c21b57a6f46ce363860203389bbeaa6
Fixed
33b5342d2080657054ddf89ef1199b426a37dae8
Fixed
94e1bfcefe8264a207c2fda2febb954e70a34b42
Fixed
6b47b29730de3232b919d8362749f6814c5f2a33

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68352.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68352.json"