Double Free Vulnerability in ath11k Driver for Linux Kernel
CVE-2026-63822

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63822?

A vulnerability exists in the ath11k driver of the Linux kernel that can lead to a double free error during firmware initialization. When an error occurs, the tx_status buffers are incorrectly released and again released when the device is unbound, resulting in a potential warning during operation. This issue is reproducible in virtual machine environments due to failures in MSI addressing initialization. To address this vulnerability, it is recommended to nullify the buffers after their initial release to prevent the double free occurrence.

Affected Version(s)

Linux d5c65159f2895379e11ca13f62feabe93278985d

Linux d5c65159f2895379e11ca13f62feabe93278985d < 0aa097a370277deab5337030b9e2d395742f469c

Linux d5c65159f2895379e11ca13f62feabe93278985d < 0a946abb82f29abe9a15173b707a449cb039b43e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.