CVE-2026-98185
Received
Received - Intake
Buffer Overflow in Linux Kernel mwifiex WiFi Driver
Vulnerability report for CVE-2026-98185, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: validate scan response extents
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the
firmware-provided BSS length from resp->size without first proving that
either extent fits. A short response or oversized BSS length can
therefore underflow tlv_buf_size and make the TLV parser walk beyond the
command response.
Compute the fixed extent from the selected normal or background scan
response. Validate that the fixed fields and BSS data fit before deriving
the TLV extent and entering the parser.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e |
| Linux | Linux | 3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |