CVE-2026-68352

Source
https://cve.org/CVERecord?id=CVE-2026-68352
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68352.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68352
Downstream
Published
2026-08-10T12:03:29.304Z
Modified
2026-08-12T04:19:22.648702948Z
Summary
wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath6kl: fix OOB read from firmware IE lengths in connect event

The firmware-controlled beaconielen, assocreqlen, and assocresplen fields in ath6klwmiconnecteventrx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->iswmmenabled.

Add a check that the total IE length fits within the buffer.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68352.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bdcd81707973cf8aa9305337166f8ee842a050d4
Fixed
1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e
Fixed
d70c0a850c21b57a6f46ce363860203389bbeaa6
Fixed
33b5342d2080657054ddf89ef1199b426a37dae8
Fixed
94e1bfcefe8264a207c2fda2febb954e70a34b42
Fixed
6b47b29730de3232b919d8362749f6814c5f2a33

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68352.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68352.json"