Linux Kernel ath11k 6GHz-Only PHY Registration Vulnerability

Vulnerability

A vulnerability in the Linux kernel's ath11k wireless driver affects the registration of 6GHz-only physical layers (PHYs) on certain hardware. Specifically, when the Board Data File (BDF) does not permit the use of the 7115MHz channel, the 6GHz-only PHY fails to register properly. This issue was identified on a Freebox V7R Board running a Linux kernel version that includes the vulnerability. The registration failure generates a warning and prevents the wireless radio from being registered with the mac80211 subsystem, ultimately leading to a failure in creating the physical device core.

Impact

The vulnerability causes 6GHz-only PHYs to fail registration, which can disrupt wireless functionality on devices that rely on this capability.

Reproduction

The vulnerability can be reproduced by attempting to register a 6GHz-only PHY on a device with a BDF that does not allow the 7115MHz channel. This will result in a registration failure, which can be observed in the system logs.

Remediation

Users can upgrade to a patched version of the Linux kernel where this issue has been addressed. The specific commit that resolves this vulnerability is available in the Linux kernel stable tree.

Added: Dec 30, 2025, 3:26 PM
Updated: Dec 30, 2025, 3:26 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
1.8
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.