CVE-2026-98190
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.
Leer descripción completaMostrar menos
A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/491df93b10d76aebaf6aa4bb05a6ba897f4fccfb
- https://git.kernel.org/stable/c/68b786691ce24c5c94e28811db243e573c50f9c1
- https://git.kernel.org/stable/c/6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304
- https://git.kernel.org/stable/c/a5b827dad8a3037cef04d0240d1c2acb1557101e
- https://git.kernel.org/stable/c/ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14
- https://git.kernel.org/stable/c/cc2ee642ebeac8699b671ddb6d5955a785e5ff43
- https://git.kernel.org/stable/c/e98ad9f4c59f2e836f8d971b57763a4277680422
- https://git.kernel.org/stable/c/f0c46f8111a479b97b8ab17747c528cade6257f1
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98190",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "e98ad9f4c59f2e836f8d971b57763a4277680422",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "f0c46f8111a479b97b8ab17747c528cade6257f1",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "a5b827dad8a3037cef04d0240d1c2acb1557101e",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "491df93b10d76aebaf6aa4bb05a6ba897f4fccfb",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "cc2ee642ebeac8699b671ddb6d5955a785e5ff43",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "68b786691ce24c5c94e28811db243e573c50f9c1",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304",
"versionType": "git"
},
{
"status": "affected",
"version": "4fb8b5aa2a1126783ae00bae544d6f3c519408ef",
"lessThan": "ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/cfg80211.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/microchip/wilc1000/cfg80211.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:04.210",
"references": [
{
"url": "https://git.kernel.org/stable/c/491df93b10d76aebaf6aa4bb05a6ba897f4fccfb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68b786691ce24c5c94e28811db243e573c50f9c1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5b827dad8a3037cef04d0240d1c2acb1557101e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc2ee642ebeac8699b671ddb6d5955a785e5ff43",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e98ad9f4c59f2e836f8d971b57763a4277680422",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f0c46f8111a479b97b8ab17747c528cade6257f1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: fix out-of-bounds read in P2P public action frames\n\nwilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once\nieee80211_is_public_action() returns true. That helper only verifies the\nframe is long enough for the action category field, that is\noffsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both\nfunctions then read the P2P public action header up to oui_subtype at\noffset 30 and pass \"size - ie_offset\" to cfg80211_find_vendor_ie(), where\nie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.\n\nA public action frame of 25 to 31 bytes passes the check but is shorter\nthan that 32 byte header, so oui_subtype can be read out of bounds, and\nbecause the length is unsigned, \"size - ie_offset\" underflows to a value\nclose to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,\nso even the size_t subtraction in mgmt_tx() is truncated to the same\nvalue. It then walks far past the buffer searching for a vendor element\nuntil it reaches unmapped memory.\n\nIn the receive path the frame arrives over the air and needs no\nassociation, so a nearby unauthenticated device can crash the host while\nit is in P2P listen. Reject frames shorter than the P2P public action\nheader in both paths before dereferencing it."
}
],
"lastModified": "2026-10-06T09:18:04.210",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}