Linux Kernel Vulnerability in ath11k WMI Commands
CVE-2026-64155

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64155?

A vulnerability in the Linux kernel's ath11k component has been identified that allows for error path leaks in certain Wireless Management Interface (WMI) Wake on Wireless (WOW) calls. This issue arises from directly returning results from ath11k_wmi_cmd_send without proper checks on the return value, which can lead to memory leaks. The identified instances fail to free the socket buffer (skb) in the event of errors, potentially compromising system stability and security. Prompt updates are recommended to mitigate these risks.

Affected Version(s)

Linux 79802b13a492d0fdeb922e98628e5ff1a8b74026

Linux 79802b13a492d0fdeb922e98628e5ff1a8b74026

Linux 79802b13a492d0fdeb922e98628e5ff1a8b74026 < 3d675896ea03aca631852a2a7e91e6cb8f664967

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.