
PEACH
Un cadre d’isolation des locataires
CVE-2026-46271 is a denial-of-service vulnerability in the Linux kernel's ath12k WiFi driver affecting Qualcomm WCN7850 hardware. The flaw causes firmware crashes when Wake-on-WLAN (WoW) offloads are incorrectly enabled on both primary and secondary links during multi-link WiFi connections. It affects Linux kernel versions 6.16.x before 6.18.14 and 6.19.x before 6.19.4. Published on June 3, 2026, it carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory).
The root cause is improper handling of Wake-on-WLAN (WoW) offload configuration in the ath12k driver's multi-link operation (MLO) code path. When a WCN7850 device establishes a multi-link WiFi connection, the driver incorrectly applies WoW offloads to both the primary and secondary links, whereas the firmware only expects them on the primary link. This logic error triggers a firmware crash, rendering the wireless interface unavailable. No specific CWE has been assigned to this vulnerability (GitHub Advisory).
Successful exploitation results in a firmware crash of the WCN7850 wireless chipset, causing a denial of service that renders the WiFi interface unavailable on the affected system. The impact is limited to the local wireless subsystem; there is no evidence of data exfiltration, privilege escalation beyond the local context, or lateral movement potential. Systems relying on wireless connectivity for critical operations would experience a loss of network availability (GitHub Advisory).
The Linux kernel has been patched to restrict WoW offloads to the primary link only. Users should update to Linux kernel version 6.18.14 or later (for the 6.16/6.18 branch) or 6.19.4 or later (for the 6.19 branch). Patches are available via the stable kernel tree at the following commits: 7379837c3f9e, e042da1085d9, and e62102ac9b77. As a temporary workaround, administrators can disable multi-link WiFi connections on WCN7850 devices or restrict WiFi connection management to trusted users (GitHub Advisory, Kernel Patch 1).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."