CVE-2026-98187
Received
Received - Intake
wifi: p54 full exp_if record required in PDR_INTERFACE_LIST
Vulnerability report for CVE-2026-98187, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
The PDR_INTERFACE_LIST loop only checks that the record start is within
the entry before reading an entire struct exp_if from it. A truncated
trailing record makes the if_id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | 2.6.24 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |