{"api_version":"1","generated_at":"2026-10-11T23:15:28+00:00","cve":"CVE-2026-98349","urls":{"html":"https://cve.report/CVE-2026-98349","api":"https://cve.report/api/cve/CVE-2026-98349.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98349","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98349"},"summary":{"title":"wifi: libipw: reject too-short beacon and probe responses","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short beacon and probe responses\n\nlibipw_process_probe_response() and the libipw_network_init() call it\nmakes assume the frame contains the full 36-byte beacon and probe\nresponse prefix, but the ipw2100 and ipw2200 receive paths only\nestablish that a management frame carries the generic 24-byte\nthree-address header.\n\nlibipw_network_init() then computes the information element length as\n\n\tstats->len - sizeof(*beacon)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() yields\n65524 for a 24-byte beacon, and the parser then walks the receive\nbuffer as if it held almost 64 KiB of information elements, reading\npast the allocation.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-10-06 09:18:28","updated_at":"2026-10-07 07:17:09"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/2c87bbc00dc93149d1dc4f803ad92d92e4ef3758","name":"https://git.kernel.org/stable/c/2c87bbc00dc93149d1dc4f803ad92d92e4ef3758","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cee6f141b3bebe62eb0363fd147acb52023935f0","name":"https://git.kernel.org/stable/c/cee6f141b3bebe62eb0363fd147acb52023935f0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b","name":"https://git.kernel.org/stable/c/5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/23afeb5d2bdfd34c8a0a661876291a4fa9978293","name":"https://git.kernel.org/stable/c/23afeb5d2bdfd34c8a0a661876291a4fa9978293","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/89959ff00a978f3172726d3d5f861ee6f1aae26d","name":"https://git.kernel.org/stable/c/89959ff00a978f3172726d3d5f861ee6f1aae26d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/19959fb60228f6dccc40d55507f8b1a751c2dc89","name":"https://git.kernel.org/stable/c/19959fb60228f6dccc40d55507f8b1a751c2dc89","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/14ae269c1306053ddf1ccf37c4bd66e085a652d1","name":"https://git.kernel.org/stable/c/14ae269c1306053ddf1ccf37c4bd66e085a652d1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ff756e6647722b7d225d882f7bdb186d8eee318e","name":"https://git.kernel.org/stable/c/ff756e6647722b7d225d882f7bdb186d8eee318e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98349","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98349","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 cee6f141b3bebe62eb0363fd147acb52023935f0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 23afeb5d2bdfd34c8a0a661876291a4fa9978293 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 89959ff00a978f3172726d3d5f861ee6f1aae26d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 14ae269c1306053ddf1ccf37c4bd66e085a652d1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 ff756e6647722b7d225d882f7bdb186d8eee318e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 2c87bbc00dc93149d1dc4f803ad92d92e4ef3758 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 19959fb60228f6dccc40d55507f8b1a751c2dc89 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b453872c35cfcbdbf5a794737817f7d4e7b1b579 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.14","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.14 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.271 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.222 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.189 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.158 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.112 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.54 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.8 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98349","cve":"CVE-2026-98349","epss":"0.001720000","percentile":"0.059930000","score_date":"2026-10-06","updated_at":"2026-10-07 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"cee6f141b3bebe62eb0363fd147acb52023935f0","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"23afeb5d2bdfd34c8a0a661876291a4fa9978293","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"89959ff00a978f3172726d3d5f861ee6f1aae26d","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"14ae269c1306053ddf1ccf37c4bd66e085a652d1","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"ff756e6647722b7d225d882f7bdb186d8eee318e","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"2c87bbc00dc93149d1dc4f803ad92d92e4ef3758","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"19959fb60228f6dccc40d55507f8b1a751c2dc89","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"},{"lessThan":"5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b","status":"affected","version":"b453872c35cfcbdbf5a794737817f7d4e7b1b579","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/wireless/intel/ipw2x00/libipw_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.14"},{"lessThan":"2.6.14","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.271","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.222","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.189","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.158","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.112","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.54","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.271","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.222","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.189","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.158","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.112","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.54","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.8","versionStartIncluding":"2.6.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc4","versionStartIncluding":"2.6.14","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short beacon and probe responses\n\nlibipw_process_probe_response() and the libipw_network_init() call it\nmakes assume the frame contains the full 36-byte beacon and probe\nresponse prefix, but the ipw2100 and ipw2200 receive paths only\nestablish that a management frame carries the generic 24-byte\nthree-address header.\n\nlibipw_network_init() then computes the information element length as\n\n\tstats->len - sizeof(*beacon)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() yields\n65524 for a 24-byte beacon, and the parser then walks the receive\nbuffer as if it held almost 64 KiB of information elements, reading\npast the allocation.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device."}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:A - The malformed input is a beacon or probe response sent over the air. The ipw2100 isr_rx and ipw2200 ipw_rx paths only check for a 24-byte header before libipw_rx_mgt() passes the frame to libipw_process_probe_response(). This is an 802.11 management frame, so the attacker must be within radio range.\nAC:L - Any beacon or probe response shorter than the 36-byte libipw_probe_response prefix triggers the bug every time. In libipw_network_init(), stats->len - sizeof(*beacon) wraps to about 65524 when truncated to u16. The attacker can send such frames repeatedly, and periodic automatic scans make the driver process probe responses.\nPR:N - Beacons and probe responses are parsed before any association or authentication, so the sender needs no credentials or relationship with the victim station.\nUI:N - The driver processes management frames on its own once the interface is up, and periodic background scans process probe responses. No user action is needed.\nS:U - The out-of-bounds read happens in the kernel's libipw receive path, and its impact stays within the kernel's own security authority.\nC:L - libipw_parse_info_param() reads up to about 64 KiB of adjacent heap past the RX skb. It copies only capped pieces (SSID, rates, WPA/RSN IEs) into the stored libipw_network, which shows up in scan results. The remote sender cannot read this back, and the leaked contents are not under its control.\nI:N - This is a read-only overrun. Every copy in libipw_parse_info_param() is bounded by the destination size (min() on ssid_len, rates_len, wpa_ie_len, rsn_ie_len), so no kernel memory is written out of bounds.\nA:H - An unauthenticated sender can repeat the frame, and each one makes the parser read about 64 KiB past a roughly 3 KB RX buffer at a different heap position. That can reach unmapped memory and oops in the RX path, and it fires KASAN or KFENCE reports. Either one takes the system down."}]}],"providerMetadata":{"dateUpdated":"2026-10-07T06:50:11.508Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/cee6f141b3bebe62eb0363fd147acb52023935f0"},{"url":"https://git.kernel.org/stable/c/23afeb5d2bdfd34c8a0a661876291a4fa9978293"},{"url":"https://git.kernel.org/stable/c/89959ff00a978f3172726d3d5f861ee6f1aae26d"},{"url":"https://git.kernel.org/stable/c/14ae269c1306053ddf1ccf37c4bd66e085a652d1"},{"url":"https://git.kernel.org/stable/c/ff756e6647722b7d225d882f7bdb186d8eee318e"},{"url":"https://git.kernel.org/stable/c/2c87bbc00dc93149d1dc4f803ad92d92e4ef3758"},{"url":"https://git.kernel.org/stable/c/19959fb60228f6dccc40d55507f8b1a751c2dc89"},{"url":"https://git.kernel.org/stable/c/5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b"}],"title":"wifi: libipw: reject too-short beacon and probe responses","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98349","datePublished":"2026-10-06T08:46:37.713Z","dateReserved":"2026-09-25T10:25:14.343Z","dateUpdated":"2026-10-07T06:50:11.508Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 09:18:28","lastModifiedDate":"2026-10-07 07:17:09","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98349","Ordinal":"1","Title":"wifi: libipw: reject too-short beacon and probe responses","CVE":"CVE-2026-98349","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98349","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short beacon and probe responses\n\nlibipw_process_probe_response() and the libipw_network_init() call it\nmakes assume the frame contains the full 36-byte beacon and probe\nresponse prefix, but the ipw2100 and ipw2200 receive paths only\nestablish that a management frame carries the generic 24-byte\nthree-address header.\n\nlibipw_network_init() then computes the information element length as\n\n\tstats->len - sizeof(*beacon)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() yields\n65524 for a 24-byte beacon, and the parser then walks the receive\nbuffer as if it held almost 64 KiB of information elements, reading\npast the allocation.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.","Type":"Description","Title":"wifi: libipw: reject too-short beacon and probe responses"}]}}}