PT-2026-106516 · Linux · Linux
CVE-2026-98187
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: require a full exp if record in PDR INTERFACE LIST
The PDR INTERFACE LIST loop only checks that the record start is within
the entry before reading an entire struct exp if from it. A truncated
trailing record makes the if id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux