{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98349","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.343Z","datePublished":"2026-10-06T08:46:37.713Z","dateUpdated":"2026-10-07T06:50:11.508Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:11.508Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short beacon and probe responses\n\nlibipw_process_probe_response() and the libipw_network_init() call it\nmakes assume the frame contains the full 36-byte beacon and probe\nresponse prefix, but the ipw2100 and ipw2200 receive paths only\nestablish that a management frame carries the generic 24-byte\nthree-address header.\n\nlibipw_network_init() then computes the information element length as\n\n\tstats->len - sizeof(*beacon)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() yields\n65524 for a 24-byte beacon, and the parser then walks the receive\nbuffer as if it held almost 64 KiB of information elements, reading\npast the allocation.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The malformed input is a beacon or probe response sent over the air. The ipw2100 isr_rx and ipw2200 ipw_rx paths only check for a 24-byte header before libipw_rx_mgt() passes the frame to libipw_process_probe_response(). This is an 802.11 management frame, so the attacker must be within radio range.\nAC:L - Any beacon or probe response shorter than the 36-byte libipw_probe_response prefix triggers the bug every time. In libipw_network_init(), stats->len - sizeof(*beacon) wraps to about 65524 when truncated to u16. The attacker can send such frames repeatedly, and periodic automatic scans make the driver process probe responses.\nPR:N - Beacons and probe responses are parsed before any association or authentication, so the sender needs no credentials or relationship with the victim station.\nUI:N - The driver processes management frames on its own once the interface is up, and periodic background scans process probe responses. No user action is needed.\nS:U - The out-of-bounds read happens in the kernel's libipw receive path, and its impact stays within the kernel's own security authority.\nC:L - libipw_parse_info_param() reads up to about 64 KiB of adjacent heap past the RX skb. It copies only capped pieces (SSID, rates, WPA/RSN IEs) into the stored libipw_network, which shows up in scan results. The remote sender cannot read this back, and the leaked contents are not under its control.\nI:N - This is a read-only overrun. Every copy in libipw_parse_info_param() is bounded by the destination size (min() on ssid_len, rates_len, wpa_ie_len, rsn_ie_len), so no kernel memory is written out of bounds.\nA:H - An unauthenticated sender can repeat the frame, and each one makes the parser read about 64 KiB past a roughly 3 KB RX buffer at a different heap position. That can reach unmapped memory and oops in the RX path, and it fires KASAN or KFENCE reports. Either one takes the system down."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"versions":[{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"cee6f141b3bebe62eb0363fd147acb52023935f0","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"23afeb5d2bdfd34c8a0a661876291a4fa9978293","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"89959ff00a978f3172726d3d5f861ee6f1aae26d","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"14ae269c1306053ddf1ccf37c4bd66e085a652d1","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"ff756e6647722b7d225d882f7bdb186d8eee318e","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"2c87bbc00dc93149d1dc4f803ad92d92e4ef3758","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"19959fb60228f6dccc40d55507f8b1a751c2dc89","status":"affected","versionType":"git"},{"version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","lessThan":"5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"versions":[{"version":"2.6.14","status":"affected"},{"version":"0","lessThan":"2.6.14","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.14","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/cee6f141b3bebe62eb0363fd147acb52023935f0"},{"url":"https://git.kernel.org/stable/c/23afeb5d2bdfd34c8a0a661876291a4fa9978293"},{"url":"https://git.kernel.org/stable/c/89959ff00a978f3172726d3d5f861ee6f1aae26d"},{"url":"https://git.kernel.org/stable/c/14ae269c1306053ddf1ccf37c4bd66e085a652d1"},{"url":"https://git.kernel.org/stable/c/ff756e6647722b7d225d882f7bdb186d8eee318e"},{"url":"https://git.kernel.org/stable/c/2c87bbc00dc93149d1dc4f803ad92d92e4ef3758"},{"url":"https://git.kernel.org/stable/c/19959fb60228f6dccc40d55507f8b1a751c2dc89"},{"url":"https://git.kernel.org/stable/c/5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b"}],"title":"wifi: libipw: reject too-short beacon and probe responses","x_generator":{"engine":"bippy-1.2.0"}}}}