目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-98348— libipw 拒绝过短关联响应漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,以下漏洞已得到解决: wifi: libipw:拒绝过短的关联响应帧 函数会读取关联响应前缀(共 30 字节)中的 capability、status 和 aid 字段,然后通过以下方式计算信息元素(Information Element)的长度: 由于 是 类型,而 返回的是 类型,因此该减法运算按 类型进行计算,结果发生回绕(wrap-around)而非变为负数。将这个结果截断为 的 长度参数时,原本短于固定字段长度的帧会被解释为接近 64 KiB 的长度,导致解析器读取超出接收缓冲区的

CVSS 7.1 · High EPSS 0.26% · P16

可能的 ATT&CK 技术 1 AI

T1200 · Hardware Additions

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6< 766268b429ae26d8ca599031fa962b0fe4673120 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< d70bdb84cf1782039384c1ffa7a18b0303c286a7 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 400b89217058fac672134a0d4092c8493dadb8ad affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 46aa75291056b6dc5faaf956dffdb3e9662477b0 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< e3025ecdb2057f866c09e059fc1466e81d6f243e affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< af1b69be19c34e28c0ae54bee954b58cd076969a affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< adb7118b7d2cfd7e8213c17d7d2829f353017754 affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-98348 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wifi: libipw: reject too-short association responses
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject too-short association responses libipw_handle_assoc_resp() reads the capability, status and aid fields of the 30-byte association response prefix and then computes the information element length as stats->len - sizeof(*frame) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() turns a frame shorter than the fixed fields into a length near 64 KiB, and the parser then reads past the receive buffer. Both the ipw2100 and ipw2200 management receive paths reach this function having established only that the frame carries the generic 24-byte three-address header. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6 ~ 766268b429ae26d8ca599031fa962b0fe4673120 -
Linux Linux 2.6.15 -

二、漏洞 CVE-2026-98348 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-98348 的情报信息

请登录查看更多情报信息。

CVE-2026-98348 补丁与修复 (8)

同批安全公告 · Linux · 2026-10-06 · 共 208 条

CVE-2026-98323 9.8 CRITICAL RDMA/siw 分片头拷贝边界漏洞
CVE-2026-98365 9.8 CRITICAL RDMA/rxe mr_check_range() 整数溢出导致越界访问漏洞
CVE-2026-98282 8.8 HIGH PowerPC IOMMU iommu_tce_check_ioba 溢出验证修复
CVE-2026-98283 8.8 HIGH KVM: PPC Book3S HV tlbie_all_lpid 使用后释放漏洞
CVE-2026-98339 8.8 HIGH cfg80211 移除过时条目时过滤BSS类型漏洞
CVE-2026-98171 8.8 HIGH smb 客户端修复复合 PDU 中 next_buffer UAF 及 NextCommand 越界漏洞
CVE-2026-98261 8.1 HIGH CIFS 服务器 cifs_chan_skip_or_disable() 函数中的使用后释放漏洞
CVE-2026-98357 8.1 HIGH IB/isert 释放连接前等待控制PDU完成漏洞
CVE-2026-98239 8.1 HIGH lan743x 网卡 RX 校验和使用后释放漏洞
CVE-2026-98341 7.8 HIGH WiFi: cfg80211驱动扫描请求释放漏洞
CVE-2026-98281 7.8 HIGH futex vfork时私有哈希分配漏洞
CVE-2026-98324 7.8 HIGH DMA引擎 pxa 硬件描述符重复计数漏洞
CVE-2026-98320 7.8 HIGH netfilter flowtable 在流释放前持有 ct 引用漏洞
CVE-2026-98228 7.8 HIGH MIPS EQE4 系统内核配置错误
CVE-2026-98229 7.8 HIGH Linux内核xfrm安全路径重置前保存输入状态数据
CVE-2026-98318 7.8 HIGH SMB客户端修复相对原生符号链接目标验证漏洞
CVE-2026-98315 7.8 HIGH NTFS运行列表更新缺少锁保护
CVE-2026-98260 7.8 HIGH exec 清理 POSIX 定时器漏洞
CVE-2026-98256 7.8 HIGH Signal 执行函数竞争条件漏洞
CVE-2026-98258 7.8 HIGH Linux内核posix-cpu-timers释放过期列表定时器漏洞

显示前 20 条,共 208 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98348

暂无评论


发表评论