CVE-2026-89524
Received Received - Intake

Buffer Underflow in Linux Kernel WiFi ath6kl Driver

Vulnerability report for CVE-2026-89524, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets ath6kl_cfg80211_connect_event() subtracts fixed IE offsets from assoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower bound. The aggregate check recently added to ath6kl_wmi_connect_event_rx() bounds the declared lengths from above (their sum must fit the received event), but an assoc request/response shorter than its fixed offset still underflows here: the u8 wraps to ~250, and cfg80211_connect_result() / cfg80211_roamed() then treat that wrapped value as the IE length and copy that many bytes out of the small assoc_info buffer to user space via nl80211, disclosing adjacent slab memory. Clamp both lengths to their offsets before subtracting. Found by 0sec (https://0sec.ai) using automated source analysis; the missing lower bound is evident from source. Compile-tested.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the ath6kl Wi-Fi driver where assoc request/response lengths are not properly clamped before subtracting fixed IE offsets. This can lead to an integer underflow, causing the length to wrap around to a large value. The driver then incorrectly copies data from a small buffer to user space, potentially exposing adjacent memory.

Detection Guidance

This vulnerability is specific to the Linux kernel's ath6kl WiFi driver and requires kernel source code analysis for detection. No direct network or system commands are provided in the context to detect this issue. Review kernel logs for WiFi-related errors or monitor for unusual memory disclosures during WiFi operations.

Impact Analysis

This vulnerability could allow an attacker to read sensitive memory from the kernel, potentially exposing passwords, encryption keys, or other confidential data. It may also enable further exploitation by providing a way to leak information or manipulate system behavior.

Compliance Impact

This vulnerability involves memory disclosure through buffer overflow in the Linux kernel's WiFi driver, which could expose adjacent slab memory to user space. Such memory leaks may lead to unauthorized data exposure, potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements if sensitive information is disclosed.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for this vulnerability. If immediate patching is not possible, disable the ath6kl WiFi driver or restrict WiFi operations to trusted networks until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89524. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart