CVE-2026-98188

Source
https://cve.org/CVERecord?id=CVE-2026-98188
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98188.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98188
Downstream
Published
2026-10-06T08:44:30Z
Modified
2026-10-08T02:52:53Z
Summary
wifi: p54: validate curve data length in the calibration curve converters
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: p54: validate curve data length in the calibration curve converters

p54_convert_rev0() and p54_convert_rev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54_convert_output_limits() and p54_convert_db() already validate their counts against the entry length; this path was missed.

Reject the entry when the counts do not fit in the entry data.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98188.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eff1a59c48e3c6a006eb4fe5f2e405a996f2259d
Fixed
81084c967c18233b19799a0c3352ebac043f31e2
Fixed
41cdf14bf4b52fbe4673a172c2a6ad756cb08111
Fixed
03d313e3dfb49a44c10a5c423452967694fb85e2
Fixed
42f4b03971f9d6329c4cbd1ea5155210d16ab65b
Fixed
4d767d6f8753db22bfc14c2724bd9cee677ffb03
Fixed
3bdcc4d61212b001b8752d80036509b4974ce16c
Fixed
b0c906107150b16925ee66da09127259864c7f36
Fixed
ce858fa6b8a214dee5adb82358885fa024cdd887

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98188.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.24
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98188.json"