CVE-2026-68353

Source
https://cve.org/CVERecord?id=CVE-2026-68353
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68353.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68353
Downstream
Published
2026-08-10T12:03:30Z
Modified
2026-08-21T03:30:34Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler

The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg.

Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68353.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bdcd81707973cf8aa9305337166f8ee842a050d4
Fixed
5297299c3fa6133275db0be99d69cd759b6cbfe9
Fixed
35196a07603f8c94a4943093bc26d5b5826285f8
Fixed
0e0fc04af9b443c6b425f00fb604ff599bc80d1d
Fixed
69ac7ba3a3df6654e7daa82674575a8c4a1a63ea
Fixed
289edc3c71344b89e6522891147cfb8f61b088bb
Fixed
eb636fbc443149b3501c3f97e26225ddcb314a0f
Fixed
c38b0d5c661951b5dd082bdf31f8a57a0ce6e540
Fixed
3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68353.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68353.json"