Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98185— wifi: mwifiex: validate scan response extents

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: wifi: mwifiex:验证扫描响应扩展字段 函数在未首先验证固定响应字段和固件提供的 BSS 长度是否有效的前提下,直接从 中减去这些值。如果响应过短或 BSS 长度过大,可能导致 发生下溢,并使 TLV 解析器越界访问命令响应数据之外的内存。 解决方案是:根据所选的正常扫描或后台扫描响应,计算固定扩展字段的长度;在推导 TLV 扩展字段并进入解析器之前,先验证固定字段和 BSS 数据是否都在有效范围内。

AI Predicted 6.5 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1200 · Hardware Additions

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 25217c5f6ce0bf3004f80c129464cd35fe9a420f affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 48312f0085aa1577d6d41af2a079b34de17c1a57 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< dccf5ecaad4d8d43c545921f20328e8f91af8698 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< c4943323fda22ef27bb6479b9d328ae48c63f64c affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 9cff2f39ed38a32070b08364c4c9346e85b8f9ec affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 7106ad8b74f50cca1ef36131f327d2c78f556daa affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 3687d7d48070838cc2953431b3a27717cab0aaf6 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: mwifiex: validate scan response extents
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: validate scan response extents mwifiex_ret_802_11_scan() subtracts the fixed response fields and the firmware-provided BSS length from resp->size without first proving that either extent fits. A short response or oversized BSS length can therefore underflow tlv_buf_size and make the TLV parser walk beyond the command response. Compute the fixed extent from the selected normal or background scan response. Validate that the fixed fields and BSS data fit before deriving the TLV extent and entering the parser.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ~ 25217c5f6ce0bf3004f80c129464cd35fe9a420f -
Linux Linux 3.0 -

II. Public POCs for CVE-2026-98185

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98185

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98185 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98185

No comments yet


Leave a comment