CVE-2026-98189
Received Received - Intake

Wifi: wilc1000 RX Buffer OOB Write Vulnerability

Vulnerability report for CVE-2026-98189, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() wilc_wlan_handle_isr_ext() takes the RX transfer size from the device-reported interrupt status register (a 15-bit field shifted left by 2, up to 131068 bytes) and reads that many bytes from the device into rx_buffer, which is only WILC_RX_BUFF_SIZE (96K) large. The wrap check only handles the current offset; the size itself is never compared against the buffer, so a bogus SDIO device can make the driver OOB-write rx_buffer by up to ~32K with data it controls. The oversized transfer also leaves rx_buffer_offset past the end of the buffer, after which the unsigned wrap check stops working and the overflow can repeat. Drop any transfer whose size exceeds the RX buffer, acknowledging the data interrupt and re-arming the RX engine so the bogus frame is discarded and reception can continue. This also restores the rx_buffer_offset <= WILC_RX_BUFF_SIZE invariant the wrap check relies on. This is not expected to change driver behavior in most cases: without this check, an oversized transfer would most likely corrupt neighboring kernel memory instead of completing anyway, and the drop path performs the same interrupt acknowledgment and RX engine re-arming as the normal path, so subsequent transfers are received unaffected. Discovered by Atuin - Automated Vulnerability Discovery Engine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux c5c77ba18ea66aa05441c71e38473efb787705a4
Linux Linux 4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a buffer overflow vulnerability in the Linux kernel's wilc1000 WiFi driver. The function wilc_wlan_handle_isr_ext() reads a device-reported transfer size from an interrupt register and copies that many bytes into a fixed-size receive buffer (96KB). If the device reports an oversized transfer (up to 131KB), the driver writes beyond the buffer, causing an out-of-bounds write. This can corrupt kernel memory and allow an attacker with control over the device to execute arbitrary code.

The vulnerability occurs because the driver does not validate the transfer size against the buffer capacity before copying data. A malicious SDIO device can exploit this to overflow the buffer by up to 32KB.

Detection Guidance

This vulnerability is specific to the Linux kernel's wilc1000 WiFi driver and involves an out-of-bounds write in the RX buffer. Detection requires checking if your system uses the affected driver version. Inspect kernel logs for errors related to wilc1000 or RX buffer overflows. Commands like 'dmesg | grep wilc1000' or 'journalctl -k | grep wilc1000' may reveal issues. Ensure your kernel version is patched or the driver is updated.

Impact Analysis

If you use a system with the vulnerable Linux kernel and a wilc1000 WiFi chip, an attacker with physical or network access to the device could exploit this to crash the system, execute arbitrary code with kernel privileges, or gain unauthorized access. This could lead to data theft, system compromise, or denial of service.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected systems may face compliance violations, legal penalties, and reputational damage if exploited. Immediate patching is recommended to maintain compliance.

Mitigation Strategies

Update your Linux kernel to the latest patched version that includes the fix for CVE-2026-98189. If using a custom or older kernel, apply the patch from the Linux kernel source. Disable the wilc1000 driver if not in use. Monitor system logs for signs of exploitation or abnormal behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart