CVE-2026-97500

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89: phy: check length before parsing PHY status IE

Hardware might report PHY status IE with unexpected length, and parser might access out of range. Check the length ahead.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 213f9e0ab2b4f35fe8d342333238c6cc91513fbfaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 98e5720afd7495eece580238f232e3b3b4c022daaffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 884495c39de1a02f42bd40051b921e2311d6ac91affected
LinuxLinux0 < 6.12.111affected
LinuxLinux0 < 6.18.53affected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References