๐Ÿ” CVE Alert

CVE-2026-64571

UNKNOWN 0.0

wifi: p54: validate RX frame length in p54_rx_eeprom_readback()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() p54_rx_eeprom_readback() copies the requested EEPROM slice out of a device-supplied readback frame without checking that the skb actually holds that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()") closed the destination overflow by copying a fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len), but the source side is still unbounded: nothing verifies the frame is long enough to supply that many bytes. A malicious USB device can send a short frame whose advertised len matches priv->eeprom_slice_size while the payload is truncated. The equality check passes and memcpy() reads past the end of the skb, leaking adjacent heap: BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) Read of size 1016 at addr ffff88800f077114 by task swapper/0/0 Call Trace: <IRQ> ... __asan_memcpy (mm/kasan/shadow.c:105) p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005) ... </IRQ> The buggy address belongs to the object at ffff88800f0770c0 which belongs to the cache skbuff_small_head of size 704 The buggy address is located 84 bytes inside of allocated 704-byte region [ffff88800f0770c0, ffff88800f077380) Check that the slice fits in the skb before copying.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7cb770729ba895f73253dfcd46c3fcba45d896f9 < 25c3b85af3fc4f8043159b14e65790fc3bbdaf48 7cb770729ba895f73253dfcd46c3fcba45d896f9 < f46f8f9c43fd02f4dd5f716d4bda296a523c04f0 7cb770729ba895f73253dfcd46c3fcba45d896f9 < d38f5d868a0a4770e3bcd0925e16c46acdbc9509 7cb770729ba895f73253dfcd46c3fcba45d896f9 < 9096e1f7014174067239a63df18ae5f28301990d 7cb770729ba895f73253dfcd46c3fcba45d896f9 < ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea
Linux / Linux
2.6.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48 git.kernel.org: https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0 git.kernel.org: https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509 git.kernel.org: https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d git.kernel.org: https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea