Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98348— wifi: libipw: reject too-short association responses

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到解决: wifi: libipw:拒绝过短的关联响应帧 函数会读取关联响应前缀(共 30 字节)中的 capability、status 和 aid 字段,然后通过以下方式计算信息元素(Information Element)的长度: 由于 是 类型,而 返回的是 类型,因此该减法运算按 类型进行计算,结果发生回绕(wrap-around)而非变为负数。将这个结果截断为 的 长度参数时,原本短于固定字段长度的帧会被解释为接近 64 KiB 的长度,导致解析器读取超出接收缓冲区的

CVSS 7.1 · High EPSS 0.26% · P16

Possible ATT&CK Techniques 1 AI

T1200 · Hardware Additions

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6< 766268b429ae26d8ca599031fa962b0fe4673120 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< d70bdb84cf1782039384c1ffa7a18b0303c286a7 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 400b89217058fac672134a0d4092c8493dadb8ad affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 46aa75291056b6dc5faaf956dffdb3e9662477b0 affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< e3025ecdb2057f866c09e059fc1466e81d6f243e affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< 14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< af1b69be19c34e28c0ae54bee954b58cd076969a affected
9e8571affd1c54b9638b4ff9844e47aae07310f6< adb7118b7d2cfd7e8213c17d7d2829f353017754 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98348

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: libipw: reject too-short association responses
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject too-short association responses libipw_handle_assoc_resp() reads the capability, status and aid fields of the 30-byte association response prefix and then computes the information element length as stats->len - sizeof(*frame) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() turns a frame shorter than the fixed fields into a length near 64 KiB, and the parser then reads past the receive buffer. Both the ipw2100 and ipw2200 management receive paths reach this function having established only that the frame carries the generic 24-byte three-address header. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6 ~ 766268b429ae26d8ca599031fa962b0fe4673120 -
Linux Linux 2.6.15 -

II. Public POCs for CVE-2026-98348

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98348

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98348 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98348

No comments yet


Leave a comment