PT-2026-106516 · Linux · Linux

CVE-2026-98187

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: require a full exp if record in PDR INTERFACE LIST
The PDR INTERFACE LIST loop only checks that the record start is within the entry before reading an entire struct exp if from it. A truncated trailing record makes the if id/variant reads cross the entry boundary into the heap beyond the EEPROM buffer (verified with a KASAN reproducer of the loop). The variant also feeds the synth front-end selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98187

Affected Products

Linux