CVE-2026-98184: wifi: mwifiex: prevent authentication frame length truncation
In the Linux kernel, the following vulnerability has been resolved:
wifi: mwifiex: prevent authentication frame length truncation
mwifiexcfg80211authenticate() derives the authentication frame length from req->ielen and req->authdatalen, both of type sizet, but stores it in a u16.
NL80211ATTRAUTHDATA only has a minimum length policy. Since nlalen is a u16, a single attribute can carry up to 65531 bytes of payload, so the sum can exceed U16MAX before it is assigned to pktlen. The truncated pktlen determines the skb frame area, while the copy length remains req->authdatalen - 4, resulting in a heap buffer overflow.
For example, with authdatalen equal to 65510 and no IEs, the sum is 65546. It is truncated to 10 and then reduced by four to 6. The driver appends only six bytes to the skb with skbput(), but then copies 65506 user-provided bytes into the authentication body.
Reaching this path requires CAPNETADMIN in the user namespace owning the network namespace, an up station netdev, and a suitable BSS/SAE authentication request.
Compute the length in sizet, reject values that cannot be represented by the firmware's u16 frame length field, and only then assign it to pktlen.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In mwifiex_cfg80211_authenticate(), compute the authentication frame length in size_t, reject sums that cannot be represented by the firmware's u16 frame-length field, and only then assign the validated value to pkt_len to prevent truncation and heap-buffer overflow.