CVE-2026-90361EPSS p11.4%
CVE-2026-90361CVE-2026-90361
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
Currently, during ath11k_service_ready_ext_event() processing,
svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
temporary allocation that is freed on the success path, but not on the
error path. If parsing succeeds far enough to allocate mac_phy_caps and
then fails on a later TLV, the allocation leaks. So free the allocation
on the error path.
Compile tested only.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.4% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-17 |