wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
Summary
| CVE | CVE-2026-68373 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:30 UTC |
| Updated | 2026-08-10 13:20:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 1264b951463a00efebe1bb596499aaad620ec8af e165a1d295e7e814e13b0f92c86e5d48309509ce git |
Not specified |
| CNA |
Linux |
Linux |
affected 1264b951463a00efebe1bb596499aaad620ec8af bcde7249d45f52f994a9872bedf45994472ade77 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1264b951463a00efebe1bb596499aaad620ec8af fb1b50ab699211e777dca5ccfb648788b6a6e519 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1264b951463a00efebe1bb596499aaad620ec8af f742d9c98b5c504fc9e6744eef13a721c2aea486 git |
Not specified |
| CNA |
Linux |
Linux |
affected 1264b951463a00efebe1bb596499aaad620ec8af 61a799ffd1e5a4fd3702d547828b7ff3d161468e git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.30 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.30 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/bcde7249d45f52f994a9872bedf45994472ade77 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f742d9c98b5c504fc9e6744eef13a721c2aea486 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fb1b50ab699211e777dca5ccfb648788b6a6e519 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/61a799ffd1e5a4fd3702d547828b7ff3d161468e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e165a1d295e7e814e13b0f92c86e5d48309509ce |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.