PT-2026-46900 · Morse Micro · Halowlink 2
CVE-2026-7762
·
Published
2026-06-05
·
Updated
2026-06-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Morse Micro HaLowLink 2 versions prior to 2.11.13
Description
A heap-based buffer overflow exists in the
dot11ah.ko HaLow Wi-Fi kernel driver. An unauthenticated attacker within radio range can cause a Denial of Service resulting in a kernel panic or potentially achieve Remote Code Execution by sending a crafted 802.11ah beacon or probe response frame. The issue occurs when a malformed S1G Capabilities Information Element (IE element ID 0xD9) is processed. Specifically, the function morse dot11ah find s1g caps for bssid() uses the IE length field as the size argument for memcpy() without validating it against the 15-byte destination buffer. This allows an attacker to supply up to 255 bytes, overflowing up to 240 bytes of controlled data into adjacent kernel heap memory during normal scanning without requiring authentication, association, or user interaction.Recommendations
Update to version 2.11.13 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Halowlink 2