← All Advisories

CVE-2026-98348

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98348

Key Details

CVECVE-2026-98348
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is none; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject too-short association responses

libipw_handle_assoc_resp() reads the capability, status and aid fields

of the 30-byte association response prefix and then computes the

information element length as

stats->len - sizeof(*frame)

stats->len is a u16 and sizeof() has type size_t, so the subtraction is

evaluated as size_t and wraps instead of going negative. Truncating

that to the u16 length parameter of libipw_parse_info_param() turns a

frame shorter than the fixed fields into a length near 64 KiB, and the

parser then reads past the receive buffer.

Both the ipw2100 and ipw2200 management receive paths reach this

function having established only that the frame carries the generic

24-byte three-address header.

Reject the frame before any fixed field is touched.

Found by an AI-assisted review of length arithmetic in management frame

parsers. Verified with a KUnit case under Generic KASAN on arm64 under

QEMU; I do not have the hardware, so it is not tested on a real device. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98348
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98348