Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-7764— Out-of-bounds read in morse.ko Vendor IE processing

AI Predicted 7.5 Difficulty: Moderate EPSS 0.13% · P3

Affected Version Matrix 1

VendorProductVersion RangeStatus
Morse MicroHaLowLink 2< 2.11.12affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-7764

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds read in morse.ko Vendor IE processing
Source: CVE Program / CVE List V5
Vulnerability Description
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element. The function morse_vendor_find_vendor_ie() does not validate the IE length against the expected structure size before its result is passed to morse_vendor_rx_caps_ops_ie() and morse_vendor_fill_sta_vendor_info(), which read at fixed offsets into the IE data. Because the length check only requires the IE to be longer than 3 bytes, an attacker can supply an undersized IE, causing a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Morse Micro HaLowLink 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Morse Micro HaLowLink是Morse Micro公司的一系列长距离无线网关设备。 Morse Micro HaLowLink 2 2.11.12之前版本存在安全漏洞,该漏洞源于morse.ko HaLow Wi-Fi内核驱动中morse_vendor_find_vendor_ie函数未验证IE长度,导致堆越界读取最多9字节,未经身份验证的攻击者可通过特制802.11ah信标或探测响应帧泄露少量内核堆内存或造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Morse MicroHaLowLink 2 0 ~ 2.11.12 -

II. Public POCs for CVE-2026-7764

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-7764

登录查看更多情报信息。

Vendor Advisories for CVE-2026-7764 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-7764

No comments yet


Leave a comment