{"id":"CVE-2026-98187","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: require a full exp_if record in PDR_INTERFACE_LIST\n\nThe PDR_INTERFACE_LIST loop only checks that the record start is within\nthe entry before reading an entir…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: require a full exp_if record in PDR_INTERFACE_LIST\n\nThe PDR_INTERFACE_LIST loop only checks that the record start is within\nthe entry before reading an entir…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < 162dbe1c285a621eab6a9f2851086b63a0378928","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < 70bf34b425fe549a4f6a8d50a319f8f05d1f91c9","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < 487f966421014de41e835bbce3feb30b35f4f729","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < bc83c04be042f53869c315b8e1eb5f124959d1d7","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < d44c1badc2dcb042985f7e37f4c448c84548b81f","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < d2fb6b588dc5bbab4f603661e41cd60f0d931628","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < d82492fd0a3fb61963c236521852763238ad3898","Linux >= eff1a59c48e3c6a006eb4fe5f2e405a996f2259d < d8efd84f49379ed28624098821f80e992657d935","Linux 2.6.24"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:03.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98187","references":[{"url":"https://git.kernel.org/stable/c/162dbe1c285a621eab6a9f2851086b63a0378928","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/487f966421014de41e835bbce3feb30b35f4f729","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70bf34b425fe549a4f6a8d50a319f8f05d1f91c9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc83c04be042f53869c315b8e1eb5f124959d1d7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2fb6b588dc5bbab4f603661e41cd60f0d931628","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d44c1badc2dcb042985f7e37f4c448c84548b81f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d82492fd0a3fb61963c236521852763238ad3898","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8efd84f49379ed28624098821f80e992657d935","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.451Z","slug":"CVE-2026-98187","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: require a full exp_if record in PDR_INTERFACE_LIST\n\nThe PDR_INTERFACE_LIST loop only checks that the record start is within\nthe entry before reading an entire struct exp_if from it. A truncated\ntrailing record makes the if_id/variant reads cross the entry boundary\ninto the heap beyond the EEPROM buffer (verified with a KASAN\nreproducer of the loop). The variant also feeds the synth front-end\nselection, so this is not only a leak.\n\nAdvance only while a full record still fits in the entry.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}