CVE-2026-98190
Received Received - Intake

Buffer Overflow in Linux Kernel WiFi Driver

Vulnerability report for CVE-2026-98190, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32. A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory. In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 4fb8b5aa2a1126783ae00bae544d6f3c519408ef
Linux Linux 5.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves an out-of-bounds read in the wilc1000 Wi-Fi driver. The issue occurs when parsing P2P public action frames. The code checks if a frame is long enough for the action category field (25 bytes) but fails to verify if it meets the minimum length for the P2P public action header (32 bytes). This allows reading beyond the frame's bounds, leading to potential crashes or memory corruption.

Detection Guidance

This vulnerability involves out-of-bounds reads in the wilc1000 WiFi driver's handling of P2P public action frames. Detection requires checking for kernel logs indicating crashes or memory corruption related to the wilc1000 module. Monitor system logs for kernel panics or oops messages involving the wifi subsystem. Commands like 'dmesg | grep wilc1000' or 'journalctl -k | grep wilc1000' may reveal issues.

Impact Analysis

An attacker within Wi-Fi range can exploit this flaw to crash the host system by sending a maliciously crafted P2P public action frame. This could lead to denial-of-service conditions, disrupting network connectivity or system stability. Systems using vulnerable Linux kernels with the wilc1000 driver are affected.

Mitigation Strategies

Apply the latest Linux kernel updates that include the fix for this vulnerability. If immediate patching is not possible, disable the wilc1000 WiFi driver by blacklisting the module or disabling WiFi functionality until the update is applied. Monitor vendor advisories for kernel updates addressing this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98190. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart