Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46248— wifi: ath12k: clear stale link mapping of ahvif->links_map

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ath12k无线驱动在非AP STA模式下MLO连接失败时未清除ahvif->links_map中的陈旧映射,可能导致触发WARN_ON。

AI Predicted 5.5 Difficulty: Easy EPSS 0.12% · P2

Possible ATT&CK Techniques 1 AI

T1014 · Rootkit

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 81e4be30544ee7e8da80e9aae7acd69d3be6d05a< da289440f04c93048d82d293b180f1cacdfee2d9 affected
81e4be30544ee7e8da80e9aae7acd69d3be6d05a< acd8319e834be6790e449701cb6df0f636801977 affected
81e4be30544ee7e8da80e9aae7acd69d3be6d05a< 2c1ba9c2adf0fda96eaaebd8799268a7506a8fc9 affected
6.15 affected
< 6.15 unaffected
6.18.14≤ 6.18.* unaffected
6.19.4≤ 6.19.* unaffected
7.0≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46248

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: ath12k: clear stale link mapping of ahvif->links_map
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->links_map When an arvif is initialized in non-AP STA mode but MLO connection preparation fails before the arvif is created (arvif->is_created remains false), the error path attempts to delete all links. However, link deletion only executes when arvif->is_created is true. As a result, ahvif retains a stale entry of arvif that is initialized but not created. When a new arvif is initialized with the same link id, this stale mapping triggers the following WARN_ON. WARNING: drivers/net/wireless/ath/ath12k/mac.c:4271 at ath12k_mac_op_change_vif_links+0x140/0x180 [ath12k], CPU#3: wpa_supplicant/275 Call trace: ath12k_mac_op_change_vif_links+0x140/0x180 [ath12k] (P) drv_change_vif_links+0xbc/0x1a4 [mac80211] ieee80211_vif_update_links+0x54c/0x6a0 [mac80211] ieee80211_vif_set_links+0x40/0x70 [mac80211] ieee80211_prep_connection+0x84/0x450 [mac80211] ieee80211_mgd_auth+0x200/0x480 [mac80211] ieee80211_auth+0x14/0x20 [mac80211] cfg80211_mlme_auth+0x90/0xf0 [cfg80211] nl80211_authenticate+0x32c/0x380 [cfg80211] genl_family_rcv_msg_doit+0xc8/0x134 Fix this issue by unassigning the link vif and clearing ahvif->links_map if arvif is only initialized but not created. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.5-01651-QCAHKSWPL_SILICONZ-1
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ath12k无线驱动在非AP STA模式下MLO连接失败时未清除ahvif->links_map中的陈旧映射,可能导致触发WARN_ON。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 81e4be30544ee7e8da80e9aae7acd69d3be6d05a ~ da289440f04c93048d82d293b180f1cacdfee2d9 -
Linux Linux 6.15 -

II. Public POCs for CVE-2026-46248

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46248

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46248 (3)

Same Patch Batch · Linux · 2026-06-03 · 32 CVEs total

CVE-2026-46244 9.1 CRITICAL netfilter: nft_inner: Fix IPv6 inner_thoff desync
CVE-2026-46266 9.1 CRITICAL inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
CVE-2026-46264 8.8 HIGH drm/xe/pf: Fix sysfs initialization
CVE-2026-46273 8.6 HIGH ibmveth: Disable GSO for packets with small MSS
CVE-2026-46251 8.4 HIGH btrfs: fix block_group_tree dirty_list corruption
CVE-2026-46270 8.4 HIGH power: supply: rt9455: Fix use-after-free in power_supply_changed()
CVE-2026-46253 7.8 HIGH pstore/ram: fix buffer overflow in persistent_ram_save_old()
CVE-2026-46259 7.8 HIGH procfs: fix missing RCU protection when reading real_parent in do_task_stat()
CVE-2026-46260 7.8 HIGH ipv6: Fix out-of-bound access in fib6_add_rt2node().
CVE-2026-46263 7.8 HIGH drm/amd/display: Fix out-of-bounds stream encoder index v3
CVE-2026-46271 7.8 HIGH wifi: ath12k: do WoW offloads only on primary link
CVE-2026-46265 7.5 HIGH RDMA/hns: Fix WQ_MEM_RECLAIM warning
CVE-2026-46250 7.3 HIGH MIPS: Work around LLVM bug when gp is used as global register variable
CVE-2026-46246 power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler
CVE-2026-46247 clk: qcom: gfx3d: add parent to parent request map
CVE-2026-46245 drm/amd/display: Fix dc_link NULL handling in HPD init
CVE-2025-71314 drm/panthor: Recover from panthor_gpu_flush_caches() failures
CVE-2025-71313 PCI: endpoint: Add missing NULL check for alloc_workqueue()
CVE-2026-46249 octeontx2-af: Fix PF driver crash with kexec kernel booting
CVE-2026-46252 regulator: core: fix locking in regulator_resolve_supply() error path

Showing top 20 of 32 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46248

No comments yet


Leave a comment