PT-2026-106519 · Linux · Linux

CVE-2026-98190

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
wilc wfi p2p rx() and mgmt tx() start parsing a frame once ieee80211 is public action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211 mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui subtype at offset 30 and pass "size - ie offset" to cfg80211 find vendor ie(), where ie offset is offsetof(struct ieee80211 mgmt, u) + sizeof(*d), i.e. 32.
A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui subtype can be read out of bounds, and because the length is unsigned, "size - ie offset" underflows to a value close to 4 GiB. cfg80211 find vendor ie() takes an unsigned int length, so even the size t subtraction in mgmt tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98190

Affected Products

Linux