CVE-2026-98184: wifi: mwifiex: prevent authentication frame length truncation

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: prevent authentication frame length truncation

mwifiexcfg80211authenticate() derives the authentication frame length from req->ielen and req->authdatalen, both of type sizet, but stores it in a u16.

NL80211ATTRAUTHDATA only has a minimum length policy. Since nlalen is a u16, a single attribute can carry up to 65531 bytes of payload, so the sum can exceed U16MAX before it is assigned to pktlen. The truncated pktlen determines the skb frame area, while the copy length remains req->authdatalen - 4, resulting in a heap buffer overflow.

For example, with authdatalen equal to 65510 and no IEs, the sum is 65546. It is truncated to 10 and then reduced by four to 6. The driver appends only six bytes to the skb with skbput(), but then copies 65506 user-provided bytes into the authentication body.

Reaching this path requires CAPNETADMIN in the user namespace owning the network namespace, an up station netdev, and a suitable BSS/SAE authentication request.

Compute the length in sizet, reject values that cannot be represented by the firmware's u16 frame length field, and only then assign it to pktlen.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In mwifiex_cfg80211_authenticate(), compute the authentication frame length in size_t, reject sums that cannot be represented by the firmware's u16 frame-length field, and only then assign the validated value to pkt_len to prevent truncation and heap-buffer overflow.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203