CVE-2026-97518: wifi: cfg80211: reject duplicate wiphy cipher suite entries
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject duplicate wiphy cipher suite entries
Duplicate entries in wiphy->ciphersuites do not describe any additional capability, but cfg80211 currently accepts them and leaves individual consumers to deal with them.
One such consumer is the WEXT compatibility code, which appends a WEP key length for each WEP cipher entry it sees. Repeated WEP entries can therefore overflow the fixed iwrange::encodingsize array returned by SIOCGIWRANGE.
Reject duplicate cipher suite entries in wiphyregister() instead. This keeps the cipher suite invariant in one place and makes malformed wiphy descriptions fail early with -EINVAL, rather than relying on a single cfg80211 user to handle duplicates correctly.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Reject duplicate cipher suite entries in wiphy_register() so malformed wiphy descriptions fail early with -EINVAL.
Event History
Frequently Asked Questions
Which systems are exposed to the affected code path?
The affected consumer is the WEXT compatibility code handling SIOCGIWRANGE. Exposure requires a wireless PHY description containing repeated WEP cipher-suite entries.
What condition causes the overflow risk?
Each repeated WEP cipher entry causes the WEXT compatibility code to append another WEP key length. Enough repeated entries can overflow the fixed iw_range::encoding_size array returned by SIOCGIWRANGE.
How does the fix prevent the issue?
The fix validates cipher suites during wiphy_register() and rejects duplicate entries with -EINVAL. This prevents malformed wireless PHY descriptions from being registered rather than leaving individual consumers to handle duplicates.