{"id":"CVE-2026-98348","summary":"wifi: libipw: reject too-short association responses","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix and then computes the\ninformation element length as\n\n\tstats-\u003elen - sizeof(*frame)\n\nstats-\u003elen is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() turns a\nframe shorter than the fixed fields into a length near 64 KiB, and the\nparser then reads past the receive buffer.\n\nBoth the ipw2100 and ipw2200 management receive paths reach this\nfunction having established only that the frame carries the generic\n24-byte three-address header.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.","modified":"2026-10-07T02:47:34.513101258Z","published":"2026-10-06T08:46:36.927Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98348.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/400b89217058fac672134a0d4092c8493dadb8ad"},{"type":"WEB","url":"https://git.kernel.org/stable/c/46aa75291056b6dc5faaf956dffdb3e9662477b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/766268b429ae26d8ca599031fa962b0fe4673120"},{"type":"WEB","url":"https://git.kernel.org/stable/c/adb7118b7d2cfd7e8213c17d7d2829f353017754"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af1b69be19c34e28c0ae54bee954b58cd076969a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d70bdb84cf1782039384c1ffa7a18b0303c286a7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e3025ecdb2057f866c09e059fc1466e81d6f243e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98348.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98348"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"9e8571affd1c54b9638b4ff9844e47aae07310f6"},{"fixed":"766268b429ae26d8ca599031fa962b0fe4673120"},{"fixed":"d70bdb84cf1782039384c1ffa7a18b0303c286a7"},{"fixed":"400b89217058fac672134a0d4092c8493dadb8ad"},{"fixed":"46aa75291056b6dc5faaf956dffdb3e9662477b0"},{"fixed":"e3025ecdb2057f866c09e059fc1466e81d6f243e"},{"fixed":"14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb"},{"fixed":"af1b69be19c34e28c0ae54bee954b58cd076969a"},{"fixed":"adb7118b7d2cfd7e8213c17d7d2829f353017754"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98348.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.15"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98348.json"}}],"schema_version":"1.9.0"}