{"id":"CVE-2026-98348","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix …","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 766268b429ae26d8ca599031fa962b0fe4673120","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < d70bdb84cf1782039384c1ffa7a18b0303c286a7","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 400b89217058fac672134a0d4092c8493dadb8ad","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 46aa75291056b6dc5faaf956dffdb3e9662477b0","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < e3025ecdb2057f866c09e059fc1466e81d6f243e","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < af1b69be19c34e28c0ae54bee954b58cd076969a","Linux >= 9e8571affd1c54b9638b4ff9844e47aae07310f6 < adb7118b7d2cfd7e8213c17d7d2829f353017754","Linux 2.6.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:27.963","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98348","references":[{"url":"https://git.kernel.org/stable/c/14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/400b89217058fac672134a0d4092c8493dadb8ad","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46aa75291056b6dc5faaf956dffdb3e9662477b0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/766268b429ae26d8ca599031fa962b0fe4673120","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adb7118b7d2cfd7e8213c17d7d2829f353017754","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af1b69be19c34e28c0ae54bee954b58cd076969a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d70bdb84cf1782039384c1ffa7a18b0303c286a7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3025ecdb2057f866c09e059fc1466e81d6f243e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.397Z","slug":"CVE-2026-98348","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix and then computes the\ninformation element length as\n\n\tstats->len - sizeof(*frame)\n\nstats->len is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() turns a\nframe shorter than the fixed fields into a length near 64 KiB, and the\nparser then reads past the receive buffer.\n\nBoth the ipw2100 and ipw2200 management receive paths reach this\nfunction having established only that the frame carries the generic\n24-byte three-address header.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}