CVE-2026-68362
Received Received - Intake

NULL Pointer Dereference in ATH11K WiFi Driver

Vulnerability report for CVE-2026-68362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set unconditionally even when ath11k_core_qmi_firmware_ready() fails. This leaves the driver in an inconsistent state where initialization is considered complete although the firmware ready handling did not finish successfully. During the subsequent SSR, the driver enters the restart path based on this incorrect state and dereferences uninitialized srng members, resulting in a NULL pointer dereference. Call trace: ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P) ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k] ath11k_core_restart+0x40/0x168 [ath11k] Fix this by: - skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set - setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds - setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling on error Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qualcomm ath11k *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL pointer dereference vulnerability in the Linux kernel's ATH11K Wi-Fi driver. It occurs when the driver incorrectly assumes initialization is complete even when firmware setup fails. This leads to a crash during subsequent operations due to uninitialized memory access.

Detection Guidance

This vulnerability is specific to the ath11k WiFi driver in the Linux kernel and may not have direct detection commands. Monitor kernel logs for NULL pointer dereference errors in ath11k modules or SSR (Subsystem Restart) events. Check for failed firmware initialization or unexpected driver restarts.

Impact Analysis

If exploited, this vulnerability could cause system crashes or instability in devices using the ATH11K Wi-Fi driver. Users may experience sudden Wi-Fi disconnections or system freezes, particularly during network operations.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this issue. If updating is not immediately possible, disable the ath11k driver or the affected WiFi hardware to prevent exploitation. Monitor vendor advisories for kernel updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart