CVE-2026-90399

Source
https://cve.org/CVERecord?id=CVE-2026-90399
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90399.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90399
Downstream
Published
2026-09-17T16:09:30Z
Modified
2026-09-19T03:47:26Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()

Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the mac_phy_caps buffer as tot_phy_id * len, where len is clamped to min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The subsequent memcpy() destination advances by sizeof(full struct) per slot via C pointer arithmetic, not by the clamped len. When firmware sends short TLVs, the second and later slots are written past the end of the allocation.

The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the buffer with full-struct pointer arithmetic, so the allocation must match that stride.

Fix by using kzalloc_objs(), which derives the element size from the pointer type, making allocation size and pointer stride provably consistent regardless of what len the firmware provides.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90399.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d889913205cf7ebda905b1e62c5867ed4e39f6c2
Fixed
d3355e0fdbbf531ca8b82a6a3feb80a1b7306a8b
Fixed
b9a5d12cbdeb860306f8d47c92caee0ea6ee0e0a
Fixed
26f8f87f0a556e7984366c64cebc16d49e15d22f
Fixed
4c6eb712a91fa079be6f9f1419c96e0ad2227081

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90399.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90399.json"