CVE-2026-68351
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar->readlen, this copies more data than the readbuf was allocated for.
Bound the memcpy to min(len - 4, ar->readlen) so that the response is still completed – avoiding repeated restarts from queued garbage – while preventing an overread past the response buffer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a84fab3cbfdc427e7d366f1cc844f27b2084c26c < f74e34e66379e487a09009a4f2d42470051672bd | affected |
| Linux | Linux | a84fab3cbfdc427e7d366f1cc844f27b2084c26c < 500c36649f270de05a56591fcc1aaaa36687958e | affected |
| Linux | Linux | a84fab3cbfdc427e7d366f1cc844f27b2084c26c < 9aee949c68dc6dccbc54333537b109c53fe2079f | affected |
| Linux | Linux | a84fab3cbfdc427e7d366f1cc844f27b2084c26c < cb7a38810cf25738176dac32dec7a146b3f959cf | affected |
| Linux | Linux | a84fab3cbfdc427e7d366f1cc844f27b2084c26c < 4cde55b2feff9504d1f993ab80e84e7ccb62791c | affected |
| Linux | Linux | 2.6.37 | affected |
| Linux | Linux | 0 < 2.6.37 | unaffected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd
- https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e
- https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f
- https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf
- https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.