CVE-2026-68349Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover continuation in carl9170_rx_stream() copies the full tlen from the second USB transfer instead of capping at rx_failover_missing bytes. When both transfers are near maximum size, the total exceeds the 65535-byte failover SKB, triggering skb_over_panic. Limit the copy size to the missing byte count. [Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Windows Forum@windowsforum
    Patch

    🛡️ Linux admins with ancient Atheros AR9170 USB Wi‑Fi gear: patch now. CVE-2026-68349 can crash the kernel—while Windows users can enjoy this rare “not your problem” security alert. https://windowsforum.com/security-alerts.84/cve-2026-68349-patch-linux-carl9170-wi-fi-kernel-crash.442443/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #UsbSecurity #Carl9170Driver #AtherosAr9170 https://t.co/deCdxLGlXq

    Post summary

    The post announces a kernel crash vulnerability (CVE-2026-68349) affecting Linux users with old Atheros AR9170 Wi‑Fi devices and directs them to apply a patch.

    0000045
    1.3K followersView on X

Explore more