← All Advisories

Linux Kernel libipw Beacon and Probe Response Parser Wraps a 16-Bit Length on Short Frames, Reading Up to 64 KiB Out of Bounds

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98349

Key Details

CVECVE-2026-98349
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is none; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject too-short beacon and probe responses

libipw_process_probe_response() and the libipw_network_init() call it

makes assume the frame contains the full 36-byte beacon and probe

response prefix, but the ipw2100 and ipw2200 receive paths only

establish that a management frame carries the generic 24-byte

three-address header.

libipw_network_init() then computes the information element length as

stats->len - sizeof(*beacon)

stats->len is a u16 and sizeof() has type size_t, so the subtraction is

evaluated as size_t and wraps instead of going negative. Truncating

that to the u16 length parameter of libipw_parse_info_param() yields

65524 for a 24-byte beacon, and the parser then walks the receive

buffer as if it held almost 64 KiB of information elements, reading

past the allocation.

Reject the frame before any fixed field is touched.

Found by an AI-assisted review of length arithmetic in management frame

parsers. Verified with a KUnit case under Generic KASAN on arm64 under

QEMU; I do not have the hardware, so it is not tested on a real device. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98349
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98349