« Volver al listado

CVE-2026-90398

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()

Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent memcpy() destination advances by sizeof(full struct) per slot via C pointer arithmetic, not by the clamped len. When firmware sends short TLVs, the second and later slots are written past the end of the allocation.

The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the buffer with full-struct pointer arithmetic, so the allocation must match that stride.

Leer descripción completaMostrar menos

Fix by using kzalloc_objs(), which derives the element size from the pointer type, making allocation size and pointer stride provably consistent regardless of what len the firmware provides.

Compile tested only.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:N) de stride mismatch en kernel permite sobreescritura de buffer con privilegios de usuario, causando DoS o corrupción de memoria del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90398",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
              "lessThan": "bbb3b3334a9ed850c5b332eedea107796e691237",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
              "lessThan": "75185e2b214e842b7e0af29e5d1fef155662b8b1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
              "lessThan": "acff2713c3212ade15051e7b421f15c89927e70f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
              "lessThan": "7a246c72132eb943b5844ba79dad597b47429dba",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/wmi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/ath/ath11k/wmi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:39.530",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/75185e2b214e842b7e0af29e5d1fef155662b8b1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a246c72132eb943b5844ba79dad597b47429dba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/acff2713c3212ade15051e7b421f15c89927e70f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bbb3b3334a9ed850c5b332eedea107796e691237",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix stride mismatch in mac_phy_caps_parse()\n\nCurrently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the\nmac_phy_caps buffer as tot_phy_id * len, where len is clamped to\nmin(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent\nmemcpy() destination advances by sizeof(full struct) per slot via C\npointer arithmetic, not by the clamped len. When firmware sends short\nTLVs, the second and later slots are written past the end of the\nallocation.\n\nThe reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the\nbuffer with full-struct pointer arithmetic, so the allocation must match\nthat stride.\n\nFix by using kzalloc_objs(), which derives the element size from the\npointer type, making allocation size and pointer stride provably\nconsistent regardless of what len the firmware provides.\n\nCompile tested only."
    }
  ],
  "lastModified": "2026-09-18T18:17:57.090",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}