PT-2026-46900 · Morse Micro · Halowlink 2

CVE-2026-7762

·

Published

2026-06-05

·

Updated

2026-06-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Morse Micro HaLowLink 2 versions prior to 2.11.13
Description A heap-based buffer overflow exists in the dot11ah.ko HaLow Wi-Fi kernel driver. An unauthenticated attacker within radio range can cause a Denial of Service resulting in a kernel panic or potentially achieve Remote Code Execution by sending a crafted 802.11ah beacon or probe response frame. The issue occurs when a malformed S1G Capabilities Information Element (IE element ID 0xD9) is processed. Specifically, the function morse dot11ah find s1g caps for bssid() uses the IE length field as the size argument for memcpy() without validating it against the 15-byte destination buffer. This allows an attacker to supply up to 255 bytes, overflowing up to 240 bytes of controlled data into adjacent kernel heap memory during normal scanning without requiring authentication, association, or user interaction.
Recommendations Update to version 2.11.13 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-7762

Affected Products

Halowlink 2