« Volver al listado

CVE-2026-97518

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: reject duplicate wiphy cipher suite entries

Duplicate entries in wiphy->cipher_suites do not describe any additional capability, but cfg80211 currently accepts them and leaves individual consumers to deal with them.

One such consumer is the WEXT compatibility code, which appends a WEP key length for each WEP cipher entry it sees. Repeated WEP entries can therefore overflow the fixed iw_range::encoding_size array returned by SIOCGIWRANGE.

Reject duplicate cipher suite entries in wiphy_register() instead. This keeps the cipher suite invariant in one place and makes malformed wiphy descriptions fail early with -EINVAL, rather than relying on a single cfg80211 user to handle duplicates correctly.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97518",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2ab658f9ce218ae93b3d2db2b3fe68bfefb81196",
              "lessThan": "1305f8b925fe92edf5fec183588dfc7db719180b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ab658f9ce218ae93b3d2db2b3fe68bfefb81196",
              "lessThan": "4cbb2360f4d8c29e67bc7a8bf6ba0ae096583923",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ab658f9ce218ae93b3d2db2b3fe68bfefb81196",
              "lessThan": "7187d145d9042b037e4f10538f70cf95e380219f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/wireless/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.32"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.32",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/wireless/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:29.787",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1305f8b925fe92edf5fec183588dfc7db719180b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4cbb2360f4d8c29e67bc7a8bf6ba0ae096583923",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7187d145d9042b037e4f10538f70cf95e380219f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: reject duplicate wiphy cipher suite entries\n\nDuplicate entries in wiphy->cipher_suites do not describe any\nadditional capability, but cfg80211 currently accepts them and leaves\nindividual consumers to deal with them.\n\nOne such consumer is the WEXT compatibility code, which appends a WEP\nkey length for each WEP cipher entry it sees. Repeated WEP entries can\ntherefore overflow the fixed iw_range::encoding_size array returned by\nSIOCGIWRANGE.\n\nReject duplicate cipher suite entries in wiphy_register() instead.\nThis keeps the cipher suite invariant in one place and makes malformed\nwiphy descriptions fail early with -EINVAL, rather than relying on a\nsingle cfg80211 user to handle duplicates correctly."
    }
  ],
  "lastModified": "2026-09-28T06:16:37.827",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}