CVE-2026-46307

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
08/06/2026
Last modified:
23/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: ath5k: do not access array OOB<br /> <br /> Vincent reports:<br /> &gt; The ath5k driver seems to do an array-index-out-of-bounds access as<br /> &gt; shown by the UBSAN kernel message:<br /> &gt; UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath5k/base.c:1741:20<br /> &gt; index 4 is out of range for type &amp;#39;ieee80211_tx_rate [4]&amp;#39;<br /> &gt; ...<br /> &gt; Call Trace:<br /> &gt; <br /> &gt; dump_stack_lvl+0x5d/0x80<br /> &gt; ubsan_epilogue+0x5/0x2b<br /> &gt; __ubsan_handle_out_of_bounds.cold+0x46/0x4b<br /> &gt; ath5k_tasklet_tx+0x4e0/0x560 [ath5k]<br /> &gt; tasklet_action_common+0xb5/0x1c0<br /> <br /> It is real. &amp;#39;ts-&gt;ts_final_idx&amp;#39; can be 3 on 5212, so:<br /> info-&gt;status.rates[ts-&gt;ts_final_idx + 1].idx = -1;<br /> with the array defined as:<br /> struct ieee80211_tx_rate rates[IEEE80211_TX_MAX_RATES];<br /> while the size is:<br /> #define IEEE80211_TX_MAX_RATES 4<br /> is indeed bogus.<br /> <br /> Set this &amp;#39;idx = -1&amp;#39; sentinel only if the array index is less than the<br /> array size. As mac80211 will not look at rates beyond the size<br /> (IEEE80211_TX_MAX_RATES).<br /> <br /> Note: The effect of the OOB write is negligible. It just overwrites the<br /> next member of info-&gt;status, i.e. ack_signal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.0 (including) 5.10.258 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.209 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.140 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.88 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.30 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.7 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*