CVE-2026-98187: wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: require a full expif record in PDRINTERFACELIST
The PDRINTERFACELIST loop only checks that the record start is within the entry before reading an entire struct expif from it. A truncated trailing record makes the ifid/variant reads cross the entry boundary into the heap beyond the EEPROM buffer (verified with a KASAN reproducer of the loop). The variant also feeds the synth front-end selection, so this is not only a leak.
Advance only while a full record still fits in the entry.