Answer in brief
CVE-2026-92496 records a Unknown severity vulnerability in wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d5c65159f2895379e11ca13f62feabe93278985d <20166fd9a4ad15d7eccc63c9dc99680aea6558ef || >=d5c65159f2895379e11ca13f62feabe93278985d <71690d26c1415e816158b45ee354367244c50d4c || >=d5c65159f2895379e11ca13f62feabe93278985d <f9726f6d97dca94ab14739c8b632301a940a7e8f || >=d5c65159f2895379e11ca13f62feabe93278985d <2677fc48dd10dc08cdec99c2692d50fe5f48dcbf || >=d5c65159f2895379e11ca13f62feabe93278985d <9652e7e23137538169f60323300cae3413475685 || >=d5c65159f2895379e11ca13f62feabe93278985d <72a5e45f606ec454ef556a68ffd92e06b0677f44 || >=d5c65159f2895379e11ca13f62feabe93278985d <9ddbc95dac167e3f2d0e3859e6ce022ae0184fc1 || >=d5c65159f2895379e11ca13f62feabe93278985d <9ef9dd30058cc9223c72f711dca1a28a5947d0c5 | 20166fd9a4ad15d7eccc63c9dc99680aea6558ef, 71690d26c1415e816158b45ee354367244c50d4c, f9726f6d97dca94ab14739c8b632301a940a7e8f, 2677fc48dd10dc08cdec99c2692d50fe5f48dcbf, 9652e7e23137538169f60323300cae3413475685, 72a5e45f606ec454ef556a68ffd92e06b0677f44, 9ddbc95dac167e3f2d0e3859e6ce022ae0184fc1, 9ef9dd30058cc9223c72f711dca1a28a5947d0c5 |
| Linux/Linuxgeneric | 5.6 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Currently, in ath11k_wmi_tlv_op_rx(), the firmware buffer is read without first verifying that the buffer has enough data to hold a header. This could result in a buffer overread. Add an upfront length check before dereferencing skb->data as a wmi_cmd_hdr. The check is placed before the trace_ath11k_wmi_event() call to preserve the existing trace semantics (tracing the full raw WMI event including the header), unlike the analogous ath12k fix which could use skb_pull_data() directly. Compile tested only.
Quoted source text, attributed separately from HOL analysis.