CVE-2026-68350: wifi: carl9170: fix OOB read from off-by-two in TX status handler
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170txprocessstatus() uses i > ((cmd->hdr.len / 2) + 1) which is off by two, allowing 2 extra iterations past valid txstatus entries when the firmware- controlled hdr.ext exceeds hdr.len/2. Fix by using the correct comparison i >= (cmd->hdr.len / 2).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68350?
CVE-2026-68350 has a risk score of 17.
How do I fix CVE-2026-68350?
To fix CVE-2026-68350, update your Linux kernel to the latest patched version that addresses this vulnerability.
What type of vulnerability is CVE-2026-68350?
CVE-2026-68350 is an out-of-bounds read vulnerability in the carl9170 wireless driver.
Which software is affected by CVE-2026-68350?
CVE-2026-68350 affects the Linux kernel, specifically within the wifi carl9170 driver.
What impact does CVE-2026-68350 have on systems?
CVE-2026-68350 could allow an attacker to read beyond the allocated memory, potentially leading to information disclosure.