CVE-2026-68199

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: ath6kl: fix OOB access from firmware ADDBA window size<br /> <br /> aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied<br /> win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not<br /> return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to<br /> compute a kzalloc size and stored in rxtid-&gt;hold_q_sz, leading to<br /> zero-size or overflowed allocations and subsequent out-of-bounds access.<br /> <br /> Clean up any previously active aggregation session for the TID first,<br /> then return early when win_sz is out of the valid range, instead of<br /> proceeding with a broken allocation size.