CVE-2026-98185

Source
https://cve.org/CVERecord?id=CVE-2026-98185
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98185.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98185
Downstream
Published
2026-10-06T08:44:27Z
Modified
2026-10-08T02:52:52Z
Summary
wifi: mwifiex: validate scan response extents
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: validate scan response extents

mwifiex_ret_802_11_scan() subtracts the fixed response fields and the firmware-provided BSS length from resp->size without first proving that either extent fits. A short response or oversized BSS length can therefore underflow tlv_buf_size and make the TLV parser walk beyond the command response.

Compute the fixed extent from the selected normal or background scan response. Validate that the fixed fields and BSS data fit before deriving the TLV extent and entering the parser.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98185.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e
Fixed
25217c5f6ce0bf3004f80c129464cd35fe9a420f
Fixed
48312f0085aa1577d6d41af2a079b34de17c1a57
Fixed
dccf5ecaad4d8d43c545921f20328e8f91af8698
Fixed
c4943323fda22ef27bb6479b9d328ae48c63f64c
Fixed
cb0008480ed7d5cf76f3ad9668a91bbb7d0b4417
Fixed
9cff2f39ed38a32070b08364c4c9346e85b8f9ec
Fixed
7106ad8b74f50cca1ef36131f327d2c78f556daa
Fixed
3687d7d48070838cc2953431b3a27717cab0aaf6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98185.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98185.json"