{"id":"CVE-2026-98185","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: validate scan response extents\n\nmwifiex_ret_802_11_scan() subtracts the fixed response fields and the\nfirmware-provided BSS length from resp->size withou…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: validate scan response extents\n\nmwifiex_ret_802_11_scan() subtracts the fixed response fields and the\nfirmware-provided BSS length from resp->size withou…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 25217c5f6ce0bf3004f80c129464cd35fe9a420f","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 48312f0085aa1577d6d41af2a079b34de17c1a57","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < dccf5ecaad4d8d43c545921f20328e8f91af8698","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < c4943323fda22ef27bb6479b9d328ae48c63f64c","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 9cff2f39ed38a32070b08364c4c9346e85b8f9ec","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 7106ad8b74f50cca1ef36131f327d2c78f556daa","Linux >= 5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e < 3687d7d48070838cc2953431b3a27717cab0aaf6","Linux 3.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:03.380","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98185","references":[{"url":"https://git.kernel.org/stable/c/25217c5f6ce0bf3004f80c129464cd35fe9a420f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3687d7d48070838cc2953431b3a27717cab0aaf6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48312f0085aa1577d6d41af2a079b34de17c1a57","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7106ad8b74f50cca1ef36131f327d2c78f556daa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cff2f39ed38a32070b08364c4c9346e85b8f9ec","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4943323fda22ef27bb6479b9d328ae48c63f64c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dccf5ecaad4d8d43c545921f20328e8f91af8698","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.450Z","slug":"CVE-2026-98185","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: validate scan response extents\n\nmwifiex_ret_802_11_scan() subtracts the fixed response fields and the\nfirmware-provided BSS length from resp->size without first proving that\neither extent fits. A short response or oversized BSS length can\ntherefore underflow tlv_buf_size and make the TLV parser walk beyond the\ncommand response.\n\nCompute the fixed extent from the selected normal or background scan\nresponse. Validate that the fixed fields and BSS data fit before deriving\nthe TLV extent and entering the parser.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}