CVE-2026-74340

Source
https://cve.org/CVERecord?id=CVE-2026-74340
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74340.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74340
Downstream
Published
2026-08-15T05:58:30.558Z
Modified
2026-08-16T03:48:35.034933611Z
Summary
wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: wcn36xx: fix OOB read from firmware count in PRINTREGINFO indication

The firmware-controlled rsp->count field is used as the loop bound for indexing into the flexible rsp->regs[] array without validation against the message length. A count exceeding the actual data causes out-of- bounds reads from the heap-allocated message buffer.

Add a check that count fits within the received message.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74340.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
43efa3c0f241e04862be8e6a68ff765d36cde1ba
Fixed
22b0b8572a64362531dd0ed499b75e16282aeb2b
Fixed
3cf92b44c4fb88a5e8de8733a4494c0956606bca
Fixed
0907c06dccae9e3c8d5a68eb9014beec73a36e79
Fixed
64228dfc4247aca178c01e5a37af7d8dcc7a6089
Fixed
23d210877968657bd07e1a517e0b516db20a1d80
Fixed
f03782f7f41f2afee5076a1ef08ced5649218771
Fixed
f987efff29a5fe45320ea5991c9d5cb98b676953
Fixed
df2187acfca6c6cca372c5d35f42394d9c270b09

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74340.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74340.json"