---
id: CVE-2026-98190
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: wilc1000: fix out-of-bounds read in P2P public action frames

  wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
  ieee80211_is_public_action() returns true…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: wilc1000: fix out-of-bounds read in P2P public action frames

  wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
  ieee80211_is_public_action() returns true…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    e98ad9f4c59f2e836f8d971b57763a4277680422
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    f0c46f8111a479b97b8ab17747c528cade6257f1
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    a5b827dad8a3037cef04d0240d1c2acb1557101e
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    491df93b10d76aebaf6aa4bb05a6ba897f4fccfb
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    cc2ee642ebeac8699b671ddb6d5955a785e5ff43
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    68b786691ce24c5c94e28811db243e573c50f9c1
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304
  - >-
    Linux >= 4fb8b5aa2a1126783ae00bae544d6f3c519408ef <
    ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14
  - Linux 5.7
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:04.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98190'
references:
  - url: 'https://git.kernel.org/stable/c/491df93b10d76aebaf6aa4bb05a6ba897f4fccfb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/68b786691ce24c5c94e28811db243e573c50f9c1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a5b827dad8a3037cef04d0240d1c2acb1557101e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc2ee642ebeac8699b671ddb6d5955a785e5ff43'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e98ad9f4c59f2e836f8d971b57763a4277680422'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f0c46f8111a479b97b8ab17747c528cade6257f1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.449Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: wilc1000: fix out-of-bounds read in P2P public action frames

wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
ieee80211_is_public_action() returns true. That helper only verifies the
frame is long enough for the action category field, that is
offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both
functions then read the P2P public action header up to oui_subtype at
offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where
ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.

A public action frame of 25 to 31 bytes passes the check but is shorter
than that 32 byte header, so oui_subtype can be read out of bounds, and
because the length is unsigned, "size - ie_offset" underflows to a value
close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,
so even the size_t subtraction in mgmt_tx() is truncated to the same
value. It then walks far past the buffer searching for a vendor element
until it reaches unmapped memory.

In the receive path the frame arrives over the air and needs no
association, so a nearby unauthenticated device can crash the host while
it is in P2P listen. Reject frames shorter than the P2P public action
header in both paths before dereferencing it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
