CVE-2026-90407 | Linux Kernel up to 6.6.156/6.12.109/6.18.51/7.2.5 ath11k ath11k_wmi_process_csa_switch_count_event num_vdevs out-of-bounds

SecurityVulns

A vulnerability was found in Linux Kernel up to 6.6.156/6.12.109/6.18.51/7.2.5. It has been declared as very critical. This issue affects the function ath11k_wmi_process_csa_switch_count_event of the component ath11k. Such manipulation of the argument num_vdevs leads to out-of-bounds read.

This vulnerability is documented as CVE-2026-90407. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More