-
CVE-2026-98183
- EPSS 0.16%
- Veröffentlicht 06.10.2026 08:44:26
- Zuletzt bearbeitet 06.10.2026 09:18:03
- Erkennungen
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: avoid out-of-bounds read for empty PREQ elements ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom fields before checking whether the element contains even the fixed header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to account for the optional Address Extension field. Consequently, an empty PREQ element causes a one-byte read beyond its declared payload. Move the helper call after both size checks, so the bottom fields are only accessed when they are present.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8b40b1d24a6099fe9fac8e207d4cb04ab5e0baae
Version <
3beddbd56946577478fd5e649f556aaaebe15b0a
Status
affected
Version
8b40b1d24a6099fe9fac8e207d4cb04ab5e0baae
Version <
e6031f02269c0f51cf67886d177f02bc300b47cd
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.2
Status
affected
Version
0
Version <
7.2
Status
unaffected
Version <=
7.2.*
Version
7.2.8
Status
unaffected
Version <=
*
Version
7.3-rc4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.048 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/3beddbd56946577478fd5e649f556aaaebe15b0a
https://git.kernel.org/stable/c/e6031f02269c0f51cf67886d177f02bc300b47cd