目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-98349— wifi: libipw 拒绝过短的信标和探测响应漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: wifi: libipw: 拒绝过短的 Beacon 和 Probe 响应帧 及其调用的 假设接收到的帧包含完整的 36 字节 Beacon 和 Probe 响应前缀。然而, 和 的接收路径仅确认管理帧携带了通用的 24 字节三地址头(three-address header)。 随后, 通过以下公式计算信息元素(Information Element)的长度: 其中, 是 类型,而 返回的类型为 。因此,该减法操作会按照 (无符号长整型)进行计算,导致发生回绕(wrap-

CVSS 7.1 · High EPSS 0.26% · P17

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux b453872c35cfcbdbf5a794737817f7d4e7b1b579< cee6f141b3bebe62eb0363fd147acb52023935f0 affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 23afeb5d2bdfd34c8a0a661876291a4fa9978293 affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 89959ff00a978f3172726d3d5f861ee6f1aae26d affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 14ae269c1306053ddf1ccf37c4bd66e085a652d1 affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< ff756e6647722b7d225d882f7bdb186d8eee318e affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 2c87bbc00dc93149d1dc4f803ad92d92e4ef3758 affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 19959fb60228f6dccc40d55507f8b1a751c2dc89 affected
b453872c35cfcbdbf5a794737817f7d4e7b1b579< 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-98349 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wifi: libipw: reject too-short beacon and probe responses
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject too-short beacon and probe responses libipw_process_probe_response() and the libipw_network_init() call it makes assume the frame contains the full 36-byte beacon and probe response prefix, but the ipw2100 and ipw2200 receive paths only establish that a management frame carries the generic 24-byte three-address header. libipw_network_init() then computes the information element length as stats->len - sizeof(*beacon) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() yields 65524 for a 24-byte beacon, and the parser then walks the receive buffer as if it held almost 64 KiB of information elements, reading past the allocation. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux b453872c35cfcbdbf5a794737817f7d4e7b1b579 ~ cee6f141b3bebe62eb0363fd147acb52023935f0 -
Linux Linux 2.6.14 -

二、漏洞 CVE-2026-98349 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-98349 的情报信息

请登录查看更多情报信息。

CVE-2026-98349 补丁与修复 (7)

同批安全公告 · Linux · 2026-10-06 · 共 208 条

CVE-2026-98323 9.8 CRITICAL RDMA/siw 分片头拷贝边界漏洞
CVE-2026-98365 9.8 CRITICAL RDMA/rxe mr_check_range() 整数溢出导致越界访问漏洞
CVE-2026-98282 8.8 HIGH PowerPC IOMMU iommu_tce_check_ioba 溢出验证修复
CVE-2026-98283 8.8 HIGH KVM: PPC Book3S HV tlbie_all_lpid 使用后释放漏洞
CVE-2026-98339 8.8 HIGH cfg80211 移除过时条目时过滤BSS类型漏洞
CVE-2026-98171 8.8 HIGH smb 客户端修复复合 PDU 中 next_buffer UAF 及 NextCommand 越界漏洞
CVE-2026-98261 8.1 HIGH CIFS 服务器 cifs_chan_skip_or_disable() 函数中的使用后释放漏洞
CVE-2026-98357 8.1 HIGH IB/isert 释放连接前等待控制PDU完成漏洞
CVE-2026-98239 8.1 HIGH lan743x 网卡 RX 校验和使用后释放漏洞
CVE-2026-98341 7.8 HIGH WiFi: cfg80211驱动扫描请求释放漏洞
CVE-2026-98281 7.8 HIGH futex vfork时私有哈希分配漏洞
CVE-2026-98324 7.8 HIGH DMA引擎 pxa 硬件描述符重复计数漏洞
CVE-2026-98320 7.8 HIGH netfilter flowtable 在流释放前持有 ct 引用漏洞
CVE-2026-98228 7.8 HIGH MIPS EQE4 系统内核配置错误
CVE-2026-98229 7.8 HIGH Linux内核xfrm安全路径重置前保存输入状态数据
CVE-2026-98318 7.8 HIGH SMB客户端修复相对原生符号链接目标验证漏洞
CVE-2026-98315 7.8 HIGH NTFS运行列表更新缺少锁保护
CVE-2026-98260 7.8 HIGH exec 清理 POSIX 定时器漏洞
CVE-2026-98256 7.8 HIGH Signal 执行函数竞争条件漏洞
CVE-2026-98258 7.8 HIGH Linux内核posix-cpu-timers释放过期列表定时器漏洞

显示前 20 条,共 208 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98349

暂无评论


发表评论