{"id":"AZL-106086","summary":"CVE-2026-98348 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix and then computes the\ninformation element length as\n\n\tstats-\u003elen - sizeof(*frame)\n\nstats-\u003elen is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() turns a\nframe shorter than the fixed fields into a length near 64 KiB, and the\nparser then reads past the receive buffer.\n\nBoth the ipw2100 and ipw2200 management receive paths reach this\nfunction having established only that the frame carries the generic\n24-byte three-address header.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.","modified":"2026-10-07T14:16:57.128778379Z","published":"2026-10-06T09:18:27Z","upstream":["CVE-2026-98348"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98348"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106086.json"}}],"schema_version":"1.9.0"}