CVE-2026-98188
Received Received - Intake

Buffer Overflow in Linux Kernel p54 WiFi Driver

Vulnerability report for CVE-2026-98188, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate curve data length in the calibration curve converters p54_convert_rev0() and p54_convert_rev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54_convert_output_limits() and p54_convert_db() already validate their counts against the entry length; this path was missed. Reject the entry when the counts do not fit in the entry data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Linux Linux 2.6.24

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's wifi driver p54. It involves an out-of-bounds read in calibration curve converters (p54_convert_rev0 and p54_convert_rev1) due to unvalidated data length from device-supplied EEPROM. Attackers could exploit malformed EEPROM entries to read beyond buffer limits.

Detection Guidance

This vulnerability affects the Linux kernel's p54 WiFi driver and requires kernel-level detection. Check if your system uses the p54 driver with lsmod | grep p54. If loaded, monitor kernel logs for out-of-bounds read warnings or crashes during WiFi operations.

Impact Analysis

This flaw could allow local attackers to cause memory corruption or system crashes by exploiting malformed EEPROM data. It may lead to denial-of-service conditions or potential privilege escalation if combined with other vulnerabilities.

Mitigation Strategies

Update your Linux kernel to the latest patched version. If using a distribution kernel, apply vendor security updates immediately. Disable the p54 driver if not needed by blacklisting it (add p54 to /etc/modprobe.d/blacklist.conf).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98188. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart