{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98348","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.343Z","datePublished":"2026-10-06T08:46:36.927Z","dateUpdated":"2026-10-07T06:50:10.352Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:10.352Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix and then computes the\ninformation element length as\n\n\tstats->len - sizeof(*frame)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() turns a\nframe shorter than the fixed fields into a length near 64 KiB, and the\nparser then reads past the receive buffer.\n\nBoth the ipw2100 and ipw2200 management receive paths reach this\nfunction having established only that the frame carries the generic\n24-byte three-address header.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The malformed input is an 802.11 Association Response management frame received over the air. ipw2100 (isr_rx path) and ipw2200 (ipw_handle_mgmt_packet) send it through libipw_rx_mgt() into libipw_handle_assoc_resp(). The attacker must be within WiFi radio range.\nAC:L - The attacker only has to send an ASSOC_RESP frame of 24-29 bytes. The drivers check only for the 24-byte header, so stats->len - sizeof(*frame) (30) wraps to about 64K in the u16 length passed to libipw_parse_info_param(). No race or special state is involved.\nPR:N - libipw_rx_mgt() processes management frames before any 802.11 authentication or key exchange. An unauthenticated nearby transmitter can inject the frame.\nUI:N - The frame is processed in the receive path as soon as the interface is up. The victim does nothing.\nS:U - The out-of-bounds read stays inside the host kernel's own memory and crosses no virtualization or IOMMU boundary.\nC:L - libipw_parse_info_param() walks up to about 64KB of memory past the receive buffer. Those bytes only fill a local libipw_network on the stack, and through the QoS IE path the qos_data that goes to firmware. Nothing is returned to the attacker, so the disclosure is limited and indirect.\nI:N - The bug is read-only. Every copy from the parsed IEs is bounded (min() on ssid/rates, an exact-size check in libipw_read_qos_param_element) and lands in the fixed-size local network struct, so nothing is written out of bounds.\nA:H - Iterating about 64KB of information elements past a few-KB skb/DMA receive buffer can hit unmapped pages (or KASAN/KFENCE) and oops the kernel. Any station in range can resend the short frame repeatedly."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"versions":[{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"766268b429ae26d8ca599031fa962b0fe4673120","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"d70bdb84cf1782039384c1ffa7a18b0303c286a7","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"400b89217058fac672134a0d4092c8493dadb8ad","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"46aa75291056b6dc5faaf956dffdb3e9662477b0","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"e3025ecdb2057f866c09e059fc1466e81d6f243e","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"af1b69be19c34e28c0ae54bee954b58cd076969a","status":"affected","versionType":"git"},{"version":"9e8571affd1c54b9638b4ff9844e47aae07310f6","lessThan":"adb7118b7d2cfd7e8213c17d7d2829f353017754","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"versions":[{"version":"2.6.15","status":"affected"},{"version":"0","lessThan":"2.6.15","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.15","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/766268b429ae26d8ca599031fa962b0fe4673120"},{"url":"https://git.kernel.org/stable/c/d70bdb84cf1782039384c1ffa7a18b0303c286a7"},{"url":"https://git.kernel.org/stable/c/400b89217058fac672134a0d4092c8493dadb8ad"},{"url":"https://git.kernel.org/stable/c/46aa75291056b6dc5faaf956dffdb3e9662477b0"},{"url":"https://git.kernel.org/stable/c/e3025ecdb2057f866c09e059fc1466e81d6f243e"},{"url":"https://git.kernel.org/stable/c/14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb"},{"url":"https://git.kernel.org/stable/c/af1b69be19c34e28c0ae54bee954b58cd076969a"},{"url":"https://git.kernel.org/stable/c/adb7118b7d2cfd7e8213c17d7d2829f353017754"}],"title":"wifi: libipw: reject too-short association responses","x_generator":{"engine":"bippy-1.2.0"}}}}