CVE-2026-98188
Received
Received - Intake
Buffer Overflow in Linux Kernel p54 WiFi Driver
Vulnerability report for CVE-2026-98188, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate curve data length in the calibration curve converters
p54_convert_rev0() and p54_convert_rev1() read calibration curve
data from the device-supplied EEPROM entry using channel and
points-per-channel counts taken verbatim from that same entry, so
an entry that declares more data than it carries drives an
out-of-bounds read past the EEPROM buffer (verified with a KASAN
reproducer of the conversion loop). The sibling converters
p54_convert_output_limits() and p54_convert_db() already validate
their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | eff1a59c48e3c6a006eb4fe5f2e405a996f2259d |
| Linux | Linux | 2.6.24 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |