CVE-2026-68352
Last modified
CVE-2026-68352 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer..
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled. Add a check that the total IE length fits within the buffer.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= bdcd81707973cf8aa9305337166f8ee842a050d4, < 1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e; >= bdcd81707973cf8aa9305337166f8ee842a050d4, < d70c0a850c21b57a6f46ce363860203389bbeaa6; >= bdcd81707973cf8aa9305337166f8ee842a050d4, < 33b5342d2080657054ddf89ef1199b426a37dae8; >= bdcd81707973cf8aa9305337166f8ee842a050d4, < 94e1bfcefe8264a207c2fda2febb954e70a34b42; >= bdcd81707973cf8aa9305337166f8ee842a050d4, < 6b47b29730de3232b919d8362749f6814c5f2a33 |
| Linux | Linux | 3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68352?
How severe is CVE-2026-68352?
How do I fix CVE-2026-68352?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68347In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68348In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68349In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6835The a+HCM developed by aEnrich has an Arbitrary File Upload …6.1
- CVE-2026-68350In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68351In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68353In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68354In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68355In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68356In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68357In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68358In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
