CVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate RX frame length in p54rxeepromreadback()
p54rxeepromreadback() copies the requested EEPROM slice out of a device-supplied readback frame without checking that the skb actually holds that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in p54rxeepromreadback()") closed the destination overflow by copying a fixed priv->eepromslicesize (and rejecting a mismatched advertised len), but the source side is still unbounded: nothing verifies the frame is long enough to supply that many bytes.
A malicious USB device can send a short frame whose advertised len matches priv->eepromslicesize while the payload is truncated. The equality check passes and memcpy() reads past the end of the skb, leaking adjacent heap:
BUG: KASAN: slab-out-of-bounds in p54rx (drivers/net/wireless/intersil/p54/txrx.c:507) Read of size 1016 at addr ffff88800f077114 by task swapper/0/0 Call Trace: <IRQ> ... asanmemcpy (mm/kasan/shadow.c:105) p54rx (drivers/net/wireless/intersil/p54/txrx.c:507) p54urxcb (drivers/net/wireless/intersil/p54/p54usb.c:163) usbhcdgivebackurb (drivers/usb/core/hcd.c:1657) dummytimer (drivers/usb/gadget/udc/dummyhcd.c:2005) ... </IRQ>
The buggy address belongs to the object at ffff88800f0770c0 which belongs to the cache skbuffsmallhead of size 704 The buggy address is located 84 bytes inside of allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)
Check that the slice fits in the skb before copying.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (wifi: p54)to a version that resolves this vulnerability.Patch da1b9a55ff11 - Configuration
Ensure p54_rx_eeprom_readback sets/uses priv->eeprom_slice_size only after validating that the advertised RX frame length matches the expected slice size (reject mismatched advertised len) so memcpy() does not read past the skb.
p54_rx_eeprom_readback (drivers/net/wireless/intersil/p54/txrx.c) priv->eeprom_slice_size = Validate against advertised RX frame length; reject mismatched advertised len - Compensating control
Mitigate exposure by preventing untrusted USB device connections (e.g., restrict/disable USB gadget/USB mass storage access) until the kernel fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64571?
The severity of CVE-2026-64571 is rated as risk 34.
How do I fix CVE-2026-64571?
To fix CVE-2026-64571, update to the latest version of the Linux kernel that resolves this vulnerability.
What type of vulnerability is CVE-2026-64571?
CVE-2026-64571 is a vulnerability related to improper validation of RX frame length in the Linux kernel.
Which software is affected by CVE-2026-64571?
CVE-2026-64571 affects the Linux kernel, specifically impacting the p54 wireless driver.
When was CVE-2026-64571 published?
CVE-2026-64571 was published on August 5, 2026.