CVE-2026-90398
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent memcpy() destination advances by sizeof(full struct) per slot via C pointer arithmetic, not by the clamped len. When firmware sends short TLVs, the second and later slots are written past the end of the allocation.
The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the buffer with full-struct pointer arithmetic, so the allocation must match that stride.
Leer descripción completaMostrar menos
Fix by using kzalloc_objs(), which derives the element size from the pointer type, making allocation size and pointer stride provably consistent regardless of what len the firmware provides.
Compile tested only.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1498.002Reflection Amplificationimpact60 % - Impacto secundario
T1561.002Disk Structure Wipeimpact55 %
Vulnerabilidad local (AV:L, PR:N) de stride mismatch en kernel permite sobreescritura de buffer con privilegios de usuario, causando DoS o corrupción de memoria del sistema.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90398",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
"lessThan": "bbb3b3334a9ed850c5b332eedea107796e691237",
"versionType": "git"
},
{
"status": "affected",
"version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
"lessThan": "75185e2b214e842b7e0af29e5d1fef155662b8b1",
"versionType": "git"
},
{
"status": "affected",
"version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
"lessThan": "acff2713c3212ade15051e7b421f15c89927e70f",
"versionType": "git"
},
{
"status": "affected",
"version": "5b90fc760db5a969ed26d70f8e62c91915f012bd",
"lessThan": "7a246c72132eb943b5844ba79dad597b47429dba",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath11k/wmi.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath11k/wmi.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:39.530",
"references": [
{
"url": "https://git.kernel.org/stable/c/75185e2b214e842b7e0af29e5d1fef155662b8b1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7a246c72132eb943b5844ba79dad597b47429dba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/acff2713c3212ade15051e7b421f15c89927e70f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bbb3b3334a9ed850c5b332eedea107796e691237",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix stride mismatch in mac_phy_caps_parse()\n\nCurrently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the\nmac_phy_caps buffer as tot_phy_id * len, where len is clamped to\nmin(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent\nmemcpy() destination advances by sizeof(full struct) per slot via C\npointer arithmetic, not by the clamped len. When firmware sends short\nTLVs, the second and later slots are written past the end of the\nallocation.\n\nThe reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the\nbuffer with full-struct pointer arithmetic, so the allocation must match\nthat stride.\n\nFix by using kzalloc_objs(), which derives the element size from the\npointer type, making allocation size and pointer stride provably\nconsistent regardless of what len the firmware provides.\n\nCompile tested only."
}
],
"lastModified": "2026-09-18T18:17:57.090",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}