
Cloud Vulnerability DB
A community-led vulnerabilities database
In the Linux kernel, a vulnerability was discovered in the ath9k_htc driver related to uninitialized value bugs. The issue was identified by Syzbot and involves missing field initialization in two functions: htc_connect_service() where svc_meta_len and pad are not initialized, and htc_issue_send() where htc_frame_hdr::control array is not initialized (Kernel Git).
The vulnerability stems from two KMSAN (Kernel Memory Sanitizer) bugs in the ath9k driver. In htc_connect_service(), the svc_meta_len and pad fields are left uninitialized. Based on the code analysis, there is no service data in the current skb, requiring svc_meta_len to be initialized to 0. Additionally, in htc_issue_send(), the htc_frame_hdr::control array is not properly initialized, though the firmware code is expected to initialize it (NVD).
The uninitialized values could lead to information leaks through USB communications. This is evidenced by the KMSAN reports showing kernel-usb-infoleak in usb_submit_urb, where uninitialized bytes are being accessed and potentially exposed (Kernel Git).
The vulnerability requires access to a system with the affected ath9k_htc driver. The issue manifests during USB communications with the device, specifically during service connection and data transmission operations (Kernel Git).
The issue has been fixed by properly initializing the affected fields. For htc_connect_service(), svc_meta_len and pad are now initialized to 0. For htc_issue_send(), the control array is zeroed using memset. The fix was implemented in the Linux kernel through a patch that addresses both initialization issues (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."