๐Ÿ” CVE Alert

CVE-2026-98190

UNKNOWN 0.0

wifi: wilc1000: fix out-of-bounds read in P2P public action frames

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32. A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory. In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4fb8b5aa2a1126783ae00bae544d6f3c519408ef < e98ad9f4c59f2e836f8d971b57763a4277680422 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < f0c46f8111a479b97b8ab17747c528cade6257f1 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < a5b827dad8a3037cef04d0240d1c2acb1557101e 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 491df93b10d76aebaf6aa4bb05a6ba897f4fccfb 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < cc2ee642ebeac8699b671ddb6d5955a785e5ff43 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 68b786691ce24c5c94e28811db243e573c50f9c1 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < 6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304 4fb8b5aa2a1126783ae00bae544d6f3c519408ef < ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14
Linux / Linux
5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e98ad9f4c59f2e836f8d971b57763a4277680422 git.kernel.org: https://git.kernel.org/stable/c/f0c46f8111a479b97b8ab17747c528cade6257f1 git.kernel.org: https://git.kernel.org/stable/c/a5b827dad8a3037cef04d0240d1c2acb1557101e git.kernel.org: https://git.kernel.org/stable/c/491df93b10d76aebaf6aa4bb05a6ba897f4fccfb git.kernel.org: https://git.kernel.org/stable/c/cc2ee642ebeac8699b671ddb6d5955a785e5ff43 git.kernel.org: https://git.kernel.org/stable/c/68b786691ce24c5c94e28811db243e573c50f9c1 git.kernel.org: https://git.kernel.org/stable/c/6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304 git.kernel.org: https://git.kernel.org/stable/c/ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14