CVE-2026-90361

Source
https://cve.org/CVERecord?id=CVE-2026-90361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90361
Downstream
Published
2026-09-17T16:09:05Z
Modified
2026-09-19T03:47:26Z
Summary
wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix leak in ath11k_service_ready_ext_event()

Currently, during ath11k_service_ready_ext_event() processing, svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a temporary allocation that is freed on the success path, but not on the error path. If parsing succeeds far enough to allocate mac_phy_caps and then fails on a later TLV, the allocation leaks. So free the allocation on the error path.

Compile tested only.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90361.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b90fc760db5a969ed26d70f8e62c91915f012bd
Fixed
35cb3086b426b3468cfc32d0d8d9883409705ea9
Fixed
854eb9053a793b73c4e8082e1923735a80c77bcd
Fixed
7dbf0bc50cf3ddd039becd875691bb7f484fa004
Fixed
1296cae53052881ddd571a9d4f467a16ebfb7f14
Fixed
10ccd92825504c029390874c6fb84c62d9f263f9
Fixed
f5bb3471c9f46c6cabc06a152c13fc518330913e
Fixed
047a817147806140cdef5fa25d69d7b7a24f905c
Fixed
0293be2212d319d59589082461abf2a9b626cd1c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90361.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90361.json"