{"id":"AZL-105999","summary":"CVE-2026-98188 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate curve data length in the calibration curve converters\n\np54_convert_rev0() and p54_convert_rev1() read calibration curve\ndata from the device-supplied EEPROM entry using channel and\npoints-per-channel counts taken verbatim from that same entry, so\nan entry that declares more data than it carries drives an\nout-of-bounds read past the EEPROM buffer (verified with a KASAN\nreproducer of the conversion loop). The sibling converters\np54_convert_output_limits() and p54_convert_db() already validate\ntheir counts against the entry length; this path was missed.\n\nReject the entry when the counts do not fit in the entry data.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:03Z","upstream":["CVE-2026-98188"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98188"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105999.json"}}],"schema_version":"1.9.0"}