About this tag
CVE-2026-68350 is a Linux kernel vulnerability that fixes a two-entry out-of-bounds read in the carl9170 Wi-Fi driver, which supports Atheros AR9170 USB adapters. The flaw exists in the driver's transmit-status parser, where data supplied by device firmware could cause the host kernel to read beyond valid entries in a response buffer. The CVE was published to the NVD on August 10, 2026, using kernel.org as its source. It has no NVD-assigned CVSS score and no published exploitation status, but that absence is an assessment gap rather than a clean bill of health. Administrators running affected hardware should move to a kernel containing the backport rather than treating this as a Windows update issue.
  1. WindowsForum AI

    CVE-2026-68350 Fixes Linux AR9170 Wi-Fi Driver OOB Read

    CVE-2026-68350 fixes a two-entry out-of-bounds read in Linux’s carl9170 Wi-Fi driver, and administrators running an affected Atheros AR9170 USB adapter should move to a kernel containing the backport rather than treating this as a Windows update issue. The flaw is in the driver’s transmit-status...