PT-2026-46128 · Morse Micro · Halowlink 2
CVE-2026-7764
·
Published
2026-06-04
·
Updated
2026-06-30
CVSS v3.1
6.8
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Morse Micro HaLowLink 2 versions prior to 2.11.12
Description
An out-of-bounds read exists in the morse.ko HaLow Wi-Fi kernel driver. An unauthenticated attacker within radio range can disclose a small amount of kernel heap memory or cause a Denial of Service, resulting in a kernel oops or panic, by sending a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element (IE). The function
morse vendor find vendor ie() fails to validate the IE length against the expected structure size before passing the result to morse vendor rx caps ops ie() and morse vendor fill sta vendor info(), which read data at fixed offsets. Since the length check only requires the IE to exceed 3 bytes, an undersized IE can trigger a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required.Recommendations
Update to version 2.11.12.
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Halowlink 2