CVE-2026-68363 | Linux Kernel up to 7.2-rc4 ath9k hif_usb.c ath9k_hif_request_firmware use after free

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4 and classified as critical. The affected element is the function ath9k_hif_request_firmware of the file drivers/net/wireless/ath/ath9k/hif_usb.c of the component ath9k. Such manipulation leads to use after free.

This vulnerability is traded as CVE-2026-68363. An attack has to be approached locally. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More