« Volver al listado

CVE-2026-98186

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length

mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a beacon/probe-response RSN or WPA information element and then walks that many 4-byte OUIs, comparing each with memcmp(). The count comes straight from the (attacker-supplied) IE and is never checked against the element's own length, and the callers admit the element on element_id alone (has_ieee_hdr() / has_vendor_hdr(), no length check).

Leer descripción completaMostrar menos

A crafted RSN/WPA IE with a large pairwise count therefore makes the walk read up to 255 * 4 bytes past the element -- an out-of-bounds read of the kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe response is processed during scan-result parsing.

Pass the number of IE bytes available at the OUI list and bound the walk to the element. Keep the length signed and reject a negative value before any unsigned arithmetic, so a small or zero IE length cannot underflow to a large size_t and defeat the bound.

Found by 0sec automated security-research tooling (https://0sec.ai).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98186",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "77e642af7f2f6029e12a35c847c56cbd0466e799",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "982b8fcdbb28f63bbbf02f0822c0bbda12ec27ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "58767b41f87244eebaa5a475b9d276c83b89b933",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "2402c9e2644b7e10c7aaaf87bf12743d7e363559",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "54a9cc5bd70b0d77a5069d4c46998c679a10c857",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "8bbef2b1ebfbadc0b9c37bbbf9c9e26fe2e41960",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "46cda9d42f0d6ec3057d878ddb1f38c0ab9f51df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e",
              "lessThan": "e667aee1c192d67d27c803007bfa9c6e0873e959",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/marvell/mwifiex/scan.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/marvell/mwifiex/scan.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:03.540",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2402c9e2644b7e10c7aaaf87bf12743d7e363559",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/46cda9d42f0d6ec3057d878ddb1f38c0ab9f51df",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/54a9cc5bd70b0d77a5069d4c46998c679a10c857",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/58767b41f87244eebaa5a475b9d276c83b89b933",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/77e642af7f2f6029e12a35c847c56cbd0466e799",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8bbef2b1ebfbadc0b9c37bbbf9c9e26fe2e41960",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/982b8fcdbb28f63bbbf02f0822c0bbda12ec27ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e667aee1c192d67d27c803007bfa9c6e0873e959",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length\n\nmwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a\nbeacon/probe-response RSN or WPA information element and then walks that\nmany 4-byte OUIs, comparing each with memcmp(). The count comes straight\nfrom the (attacker-supplied) IE and is never checked against the\nelement's own length, and the callers admit the element on element_id\nalone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted\nRSN/WPA IE with a large pairwise count therefore makes the walk read up\nto 255 * 4 bytes past the element -- an out-of-bounds read of the\nkmemdup()'d beacon buffer, reachable from any AP whose beacon/probe\nresponse is processed during scan-result parsing.\n\nPass the number of IE bytes available at the OUI list and bound the walk\nto the element. Keep the length signed and reject a negative value\nbefore any unsigned arithmetic, so a small or zero IE length cannot\nunderflow to a large size_t and defeat the bound.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."
    }
  ],
  "lastModified": "2026-10-06T09:18:03.540",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}