CVE-2026-98190
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.
A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < e98ad9f4c59f2e836f8d971b57763a4277680422 | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < f0c46f8111a479b97b8ab17747c528cade6257f1 | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < a5b827dad8a3037cef04d0240d1c2acb1557101e | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 491df93b10d76aebaf6aa4bb05a6ba897f4fccfb | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < cc2ee642ebeac8699b671ddb6d5955a785e5ff43 | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 68b786691ce24c5c94e28811db243e573c50f9c1 | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304 | affected |
| Linux | Linux | 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 | affected |
| Linux | Linux | 5.7 | affected |
| Linux | Linux | 0 < 5.7 | unaffected |
| Linux | Linux | 5.10.271 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.222 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.189 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.158 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e98ad9f4c59f2e836f8d971b57763a4277680422
- https://git.kernel.org/stable/c/f0c46f8111a479b97b8ab17747c528cade6257f1
- https://git.kernel.org/stable/c/a5b827dad8a3037cef04d0240d1c2acb1557101e
- https://git.kernel.org/stable/c/491df93b10d76aebaf6aa4bb05a6ba897f4fccfb
- https://git.kernel.org/stable/c/cc2ee642ebeac8699b671ddb6d5955a785e5ff43
- https://git.kernel.org/stable/c/68b786691ce24c5c94e28811db243e573c50f9c1
- https://git.kernel.org/stable/c/6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304
- https://git.kernel.org/stable/c/ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.