PT-2026-106517 · Linux · Linux

CVE-2026-98188

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate curve data length in the calibration curve converters
p54 convert rev0() and p54 convert rev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54 convert output limits() and p54 convert db() already validate their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98188

Affected Products

Linux