---
id: CVE-2026-90408
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()

  There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
  the parse infras…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()

  There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
  the parse infras…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d889913205cf7ebda905b1e62c5867ed4e39f6c2 <
    bf97c9d5123859a07848462539153176db029f3a
  - >-
    Linux >= d889913205cf7ebda905b1e62c5867ed4e39f6c2 <
    878654eb78c6aa0ff585baf1376567c775ca28ec
  - Linux 6.3
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:57.940'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90408'
references:
  - url: 'https://git.kernel.org/stable/c/878654eb78c6aa0ff585baf1376567c775ca28ec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bf97c9d5123859a07848462539153176db029f3a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00175
epssPercentile: 0.06126
ingestedAt: '2026-09-17T16:21:47.798Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath12k: fix overreads in ath12k_wmi_process_csa_switch_count_event()

There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
the parse infrastructure does not enforce a minimum length for the event
struct. Additionally, the num_vdevs field is taken directly from firmware
and used as a loop bound over the vdev_ids array without checking that it
fits within the TLV payload. Either condition can cause an out-of-bounds
read.

Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so
the parse infrastructure enforces a minimum length for the fixed-size event
struct. Add a helper ath12k_wmi_tlv_data_len() to recover the payload
length of a parsed TLV from the header preceding its data pointer. Use it
in ath12k_wmi_process_csa_switch_count_event() to bound num_vdevs before
the loop.

Compile tested only.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
