๐Ÿ” CVE Alert

CVE-2026-7763

CRITICAL 9.8

Heap buffer overflow in morse.ko TIM IE processing

CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
17th

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.

Vendor morse micro
Product halowlink 2
Published Jun 5, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for morse micro halowlink 2

Be the first to know when new critical vulnerabilities affecting morse micro halowlink 2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Morse Micro / HaLowLink 2
0 < 2.11.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
morsemicro.com: https://www.morsemicro.com/security-advisories/MM-SA-2026-001