{"id":"CVE-2026-98187","summary":"wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: require a full exp_if record in PDR_INTERFACE_LIST\n\nThe PDR_INTERFACE_LIST loop only checks that the record start is within\nthe entry before reading an entire struct exp_if from it. A truncated\ntrailing record makes the if_id/variant reads cross the entry boundary\ninto the heap beyond the EEPROM buffer (verified with a KASAN\nreproducer of the loop). The variant also feeds the synth front-end\nselection, so this is not only a leak.\n\nAdvance only while a full record still fits in the entry.","modified":"2026-10-08T02:52:51.830013849Z","published":"2026-10-06T08:44:29.258Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98187.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/162dbe1c285a621eab6a9f2851086b63a0378928"},{"type":"WEB","url":"https://git.kernel.org/stable/c/487f966421014de41e835bbce3feb30b35f4f729"},{"type":"WEB","url":"https://git.kernel.org/stable/c/70bf34b425fe549a4f6a8d50a319f8f05d1f91c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bc83c04be042f53869c315b8e1eb5f124959d1d7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d2fb6b588dc5bbab4f603661e41cd60f0d931628"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d44c1badc2dcb042985f7e37f4c448c84548b81f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d82492fd0a3fb61963c236521852763238ad3898"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d8efd84f49379ed28624098821f80e992657d935"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98187.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98187"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"eff1a59c48e3c6a006eb4fe5f2e405a996f2259d"},{"fixed":"162dbe1c285a621eab6a9f2851086b63a0378928"},{"fixed":"70bf34b425fe549a4f6a8d50a319f8f05d1f91c9"},{"fixed":"487f966421014de41e835bbce3feb30b35f4f729"},{"fixed":"bc83c04be042f53869c315b8e1eb5f124959d1d7"},{"fixed":"d44c1badc2dcb042985f7e37f4c448c84548b81f"},{"fixed":"d2fb6b588dc5bbab4f603661e41cd60f0d931628"},{"fixed":"d82492fd0a3fb61963c236521852763238ad3898"},{"fixed":"d8efd84f49379ed28624098821f80e992657d935"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98187.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.24"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98187.json"}}],"schema_version":"1.9.0"}