CVE-2026-98185
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: validate scan response extents
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the firmware-provided BSS length from resp->size without first proving that either extent fits. A short response or oversized BSS length can therefore underflow tlv_buf_size and make the TLV parser walk beyond the command response.
Compute the fixed extent from the selected normal or background scan response. Validate that the fixed fields and BSS data fit before deriving the TLV extent and entering the parser.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 25217c5f6ce0bf3004f80c129464cd35fe9a420f | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 48312f0085aa1577d6d41af2a079b34de17c1a57 | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < dccf5ecaad4d8d43c545921f20328e8f91af8698 | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < c4943323fda22ef27bb6479b9d328ae48c63f64c | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417 | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 9cff2f39ed38a32070b08364c4c9346e85b8f9ec | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 7106ad8b74f50cca1ef36131f327d2c78f556daa | affected |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 3687d7d48070838cc2953431b3a27717cab0aaf6 | affected |
| Linux | Linux | 3.0 | affected |
| Linux | Linux | 0 < 3.0 | unaffected |
| Linux | Linux | 5.10.271 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.222 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.189 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.158 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/25217c5f6ce0bf3004f80c129464cd35fe9a420f
- https://git.kernel.org/stable/c/48312f0085aa1577d6d41af2a079b34de17c1a57
- https://git.kernel.org/stable/c/dccf5ecaad4d8d43c545921f20328e8f91af8698
- https://git.kernel.org/stable/c/c4943323fda22ef27bb6479b9d328ae48c63f64c
- https://git.kernel.org/stable/c/cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417
- https://git.kernel.org/stable/c/9cff2f39ed38a32070b08364c4c9346e85b8f9ec
- https://git.kernel.org/stable/c/7106ad8b74f50cca1ef36131f327d2c78f556daa
- https://git.kernel.org/stable/c/3687d7d48070838cc2953431b3a27717cab0aaf6
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.