CVE-2026-92497

Source
https://cve.org/CVERecord?id=CVE-2026-92497
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92497.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92497
Downstream
Published
2026-09-17T16:10:12Z
Modified
2026-09-19T03:47:31Z
Summary
wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()

Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread.

Update the logic to verify the buffer contains at least enough data to hold a wmi_cmd_hdr before reading from the buffer.

Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92497.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d889913205cf7ebda905b1e62c5867ed4e39f6c2
Fixed
9784faa6afd26693287e8e4569bdedee00212909
Fixed
07659388110de004cbb753f3c7bc85e657e51f7a
Fixed
95d1bd1db9e9d8eccffc880166e01c4775115716
Fixed
9e6ec0977f0b9c16fc20efea050e3eea8f66e34b
Fixed
7698656a2f7b045af5a6859766238cefea1b1945

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92497.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92497.json"