CVE-2026-98186: wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length

mwifiexsearchouiinie() reads a pairwise-cipher (PTK) count from a beacon/probe-response RSN or WPA information element and then walks that many 4-byte OUIs, comparing each with memcmp(). The count comes straight from the (attacker-supplied) IE and is never checked against the element's own length, and the callers admit the element on elementid alone (hasieeehdr() / hasvendorhdr(), no length check). A crafted RSN/WPA IE with a large pairwise count therefore makes the walk read up to 255 4 bytes past the element -- an out-of-bounds read of the kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe response is processed during scan-result parsing.

Pass the number of IE bytes available at the OUI list and bound the walk to the element. Keep the length signed and reject a negative value before any unsigned arithmetic, so a small or zero IE length cannot underflow to a large sizet and defeat the bound.

Found by 0sec automated security-research tooling (https://0sec.ai).

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:25 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger this vulnerability?

Any nearby or otherwise reachable Wi-Fi access point whose beacon or probe response is processed during scan-result parsing can supply the crafted RSN or WPA information element. Exploitation does not require association with the access point.

2

What malformed input is required?

The attacker needs an RSN or WPA information element with a pairwise-cipher count that is large relative to the element's actual length. The vulnerable code trusts that count and can read beyond the copied beacon buffer while walking 4-byte cipher OUIs.

3

How can I tell whether a system is affected?

Affected systems use the Linux kernel mwifiex Wi-Fi driver and process scan results containing RSN or WPA information elements. The provided data does not identify specific kernel versions; verify whether the applicable stable fixes referenced in the advisory are present.

4

What mitigation is available if the fix cannot be deployed immediately?

The issue is reachable when scanning parses beacon or probe-response data from access points. Reducing exposure to untrusted Wi-Fi radio environments may limit opportunities for malicious beacon or probe-response frames, but the data provides no complete workaround other than applying the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203