Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98186— wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: wifi: mwifiex:将成对密码 OUI 遍历限制在信息元素(IE)长度内 函数从信标(beacon)或探测响应(probe-response)的 RSN 或 WPA 信息元素(IE)中读取一个成对密码(PTK)计数,然后基于该计数遍历相应数量的 4 字节 OUI,并使用 逐一比较。该计数直接来自(攻击者提供的)IE,且从未与 IE 自身的长度进行校验。此外,调用方仅依据 接受该元素(通过 / 检查,缺乏长度校验)。因此,构造一个具有较大成对密码计数的恶意 RSN/W

AI Predicted 5.3 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 77e642af7f2f6029e12a35c847c56cbd0466e799 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 982b8fcdbb28f63bbbf02f0822c0bbda12ec27ed affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 58767b41f87244eebaa5a475b9d276c83b89b933 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 2402c9e2644b7e10c7aaaf87bf12743d7e363559 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 54a9cc5bd70b0d77a5069d4c46998c679a10c857 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 8bbef2b1ebfbadc0b9c37bbbf9c9e26fe2e41960 affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< 46cda9d42f0d6ec3057d878ddb1f38c0ab9f51df affected
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e< e667aee1c192d67d27c803007bfa9c6e0873e959 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98186

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a beacon/probe-response RSN or WPA information element and then walks that many 4-byte OUIs, comparing each with memcmp(). The count comes straight from the (attacker-supplied) IE and is never checked against the element's own length, and the callers admit the element on element_id alone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted RSN/WPA IE with a large pairwise count therefore makes the walk read up to 255 * 4 bytes past the element -- an out-of-bounds read of the kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe response is processed during scan-result parsing. Pass the number of IE bytes available at the OUI list and bound the walk to the element. Keep the length signed and reject a negative value before any unsigned arithmetic, so a small or zero IE length cannot underflow to a large size_t and defeat the bound. Found by 0sec automated security-research tooling (https://0sec.ai).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e ~ 77e642af7f2f6029e12a35c847c56cbd0466e799 -
Linux Linux 3.0 -

II. Public POCs for CVE-2026-98186

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98186

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98186 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98186

No comments yet


Leave a comment