Linux Kernel ath11k WMI WOW Calls Error Path Leak Vulnerability

Vulnerability

A vulnerability in the Linux kernel's ath11k wireless driver has been addressed, which involved improper error handling in certain Wake on Wireless (WoW) commands. The issue arose because the return value of a command sending function was not checked, leading to a failure to free a buffer in case of an error. This vulnerability affects the Linux kernel stable tree.

Impact

The vulnerability could lead to memory management issues, specifically buffer leaks, which may be exploited to cause unintended behavior in the system.

Reproduction

The vulnerability can be reproduced by invoking the WMI WoW host wakeup indication command or the WMI WoW enable command in the ath11k driver. These commands can be sent without proper error handling, allowing the vulnerability to manifest.

Remediation

Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.

Added: Jul 19, 2026, 4:51 PM
Updated: Jul 19, 2026, 4:51 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
9.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.