CVE-2026-98185
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: validate scan response extents
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the firmware-provided BSS length from resp->size without first proving that either extent fits. A short response or oversized BSS length can therefore underflow tlv_buf_size and make the TLV parser walk beyond the command response.
Compute the fixed extent from the selected normal or background scan response. Validate that the fixed fields and BSS data fit before deriving the TLV extent and entering the parser.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/25217c5f6ce0bf3004f80c129464cd35fe9a420f
- https://git.kernel.org/stable/c/3687d7d48070838cc2953431b3a27717cab0aaf6
- https://git.kernel.org/stable/c/48312f0085aa1577d6d41af2a079b34de17c1a57
- https://git.kernel.org/stable/c/7106ad8b74f50cca1ef36131f327d2c78f556daa
- https://git.kernel.org/stable/c/9cff2f39ed38a32070b08364c4c9346e85b8f9ec
- https://git.kernel.org/stable/c/c4943323fda22ef27bb6479b9d328ae48c63f64c
- https://git.kernel.org/stable/c/cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417
- https://git.kernel.org/stable/c/dccf5ecaad4d8d43c545921f20328e8f91af8698
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98185",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "25217c5f6ce0bf3004f80c129464cd35fe9a420f",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "48312f0085aa1577d6d41af2a079b34de17c1a57",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "dccf5ecaad4d8d43c545921f20328e8f91af8698",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "c4943323fda22ef27bb6479b9d328ae48c63f64c",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "9cff2f39ed38a32070b08364c4c9346e85b8f9ec",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "7106ad8b74f50cca1ef36131f327d2c78f556daa",
"versionType": "git"
},
{
"status": "affected",
"version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
"lessThan": "3687d7d48070838cc2953431b3a27717cab0aaf6",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/scan.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/marvell/mwifiex/scan.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:03.380",
"references": [
{
"url": "https://git.kernel.org/stable/c/25217c5f6ce0bf3004f80c129464cd35fe9a420f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3687d7d48070838cc2953431b3a27717cab0aaf6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/48312f0085aa1577d6d41af2a079b34de17c1a57",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7106ad8b74f50cca1ef36131f327d2c78f556daa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9cff2f39ed38a32070b08364c4c9346e85b8f9ec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4943323fda22ef27bb6479b9d328ae48c63f64c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dccf5ecaad4d8d43c545921f20328e8f91af8698",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: validate scan response extents\n\nmwifiex_ret_802_11_scan() subtracts the fixed response fields and the\nfirmware-provided BSS length from resp->size without first proving that\neither extent fits. A short response or oversized BSS length can\ntherefore underflow tlv_buf_size and make the TLV parser walk beyond the\ncommand response.\n\nCompute the fixed extent from the selected normal or background scan\nresponse. Validate that the fixed fields and BSS data fit before deriving\nthe TLV extent and entering the parser."
}
],
"lastModified": "2026-10-06T09:18:03.380",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}