{"id":"CVE-2026-89524","title":"kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (CVE-2026-89524)","summary":"A flaw was found in the ath6kl Wi-Fi driver of the Linux kernel. An integer underflow vulnerability occurs when processing Wi-Fi association requests or responses that are shorter than expected. This can cause the system to read beyond the…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Linux","affected":["Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < 225587bdbf4b0eb5265a71ee4dc183561a1857fc","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < d337213a889705a69735079606d0b4c672b17605","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < e11d5ae96d5e52cb48fa27c6ad352d766d0322fb","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < 6deb4d7a0c3d91821b2a8d5239e3d9933d9217d9","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < e3619bed5da125713b29ac881dc66f5e06606f88","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < e1330d719c047c4d8190a16be034b29fc601a815","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < 8eb73016fb3968cf2db3987a92764563a3af773a","Linux >= bdcd81707973cf8aa9305337166f8ee842a050d4 < 3bbd05723d15dd06f0560bcd94fbf9a91b5f5613","Linux 3.2"],"published":"2026-09-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T12:14:01+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89524.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89524.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89524"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532320"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89524"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89524"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89524.mbox"},{"url":"https://git.kernel.org/stable/c/225587bdbf4b0eb5265a71ee4dc183561a1857fc"},{"url":"https://git.kernel.org/stable/c/d337213a889705a69735079606d0b4c672b17605"},{"url":"https://git.kernel.org/stable/c/e11d5ae96d5e52cb48fa27c6ad352d766d0322fb"},{"url":"https://git.kernel.org/stable/c/6deb4d7a0c3d91821b2a8d5239e3d9933d9217d9"},{"url":"https://git.kernel.org/stable/c/e3619bed5da125713b29ac881dc66f5e06606f88"},{"url":"https://git.kernel.org/stable/c/e1330d719c047c4d8190a16be034b29fc601a815"},{"url":"https://git.kernel.org/stable/c/8eb73016fb3968cf2db3987a92764563a3af773a"},{"url":"https://git.kernel.org/stable/c/3bbd05723d15dd06f0560bcd94fbf9a91b5f5613"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00419,"epssPercentile":0.33467,"scores":{"vendor":5.5,"cna":8.1},"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89524","body":"## Overview\n\nA flaw was found in the ath6kl Wi-Fi driver of the Linux kernel. An integer underflow vulnerability occurs when processing Wi-Fi association requests or responses that are shorter than expected. This can cause the system to read beyond the intended buffer, leading to the disclosure of adjacent memory to a remote attacker. This information disclosure could potentially expose sensitive data.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89524.json)\n\n**kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205452,"id":"CVE-2026-89524","ts":1789576718924,"field":"cvss","old":"8.1","new":"5.5"},{"seq":205451,"id":"CVE-2026-89524","ts":1789576718924,"field":"severity","old":"high","new":"medium"},{"seq":197973,"id":"CVE-2026-89524","ts":1789384321209,"field":"cvss","old":"6.4","new":"8.1"},{"seq":197972,"id":"CVE-2026-89524","ts":1789384321209,"field":"severity","old":"medium","new":"high"},{"seq":183768,"id":"CVE-2026-89524","ts":1789356677305,"field":"cvss","old":"8.1","new":"6.4"},{"seq":183767,"id":"CVE-2026-89524","ts":1789356677305,"field":"severity","old":"high","new":"medium"},{"seq":153316,"id":"CVE-2026-89524","ts":1789285350015,"field":"cvss","old":null,"new":"8.1"},{"seq":153315,"id":"CVE-2026-89524","ts":1789285350015,"field":"severity","old":"none","new":"high"},{"seq":147385,"id":"CVE-2026-89524","ts":1789270210696,"field":"cvss","old":null,"new":"6.4"},{"seq":147384,"id":"CVE-2026-89524","ts":1789270210696,"field":"severity","old":"none","new":"medium"},{"seq":109141,"id":"CVE-2026-89524","ts":1789183730470,"field":"cvss","old":null,"new":"6.4"},{"seq":109140,"id":"CVE-2026-89524","ts":1789183730470,"field":"severity","old":"none","new":"medium"}]}