SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89524

HIGH · CVSS 8.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ath6kl driver, where insufficient validation of association request and response lengths can lead to an underflow condition. This flaw allows for the disclosure of adjacent slab memory to user space, potentially exposing sensitive information. Organizations using Linux systems with ath6kl wireless drivers should prioritize addressing this issue to mitigate the risk of data leakage.

CVE
CVE-2026-89524
Severity
HIGH
CVSS
8.1
EPSS
0.26%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets ath6kl_cfg80211_connect_event() subtracts fixed IE offsets from assoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower bound. The aggregate check recently added to ath6kl_wmi_connect_event_rx() bounds the declared lengths from above (their sum must fit the received event), but an assoc request/response shorter than its fixed offset still underflows here: the u8 wraps to ~250, and cfg80211_connect_result() / cfg80211_roamed() then treat that wrapped value as the IE length and copy that many bytes out of the small assoc_info buffer to user space via nl80211, disclosing adjacent slab memory. Clamp both lengths to their offsets before subtracting. Found by 0sec (https://0sec.ai) using automated source analysis; the missing lower bound is evident from source. Compile-tested.