In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170txprocess_status() uses
i > ((cmd->hdr.len / 2) + 1) which is off by two, allowing
2 extra iterations past valid txstatus entries when the firmware-
controlled hdr.ext exceeds hdr.len/2. Fix by using the correct
comparison i >= (cmd->hdr.len / 2).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68350.json",
"cna_assigner": "Linux"
}