CVE-2026-98348: wifi: libipw: reject too-short association responses

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject too-short association responses

libipwhandleassocresp() reads the capability, status and aid fields of the 30-byte association response prefix and then computes the information element length as

stats->len - sizeof(frame)

stats->len is a u16 and sizeof() has type sizet, so the subtraction is evaluated as sizet and wraps instead of going negative. Truncating that to the u16 length parameter of libipwparseinfoparam() turns a frame shorter than the fixed fields into a length near 64 KiB, and the parser then reads past the receive buffer.

Both the ipw2100 and ipw2200 management receive paths reach this function having established only that the frame carries the generic 24-byte three-address header.

Reject the frame before any fixed field is touched.

Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Reject association response frames shorter than the fixed 30-byte association response prefix before accessing capability, status, or AID fields.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's libipw code through the ipw2100 or ipw2200 wireless management receive paths are exposed. The affected paths can reach the vulnerable association-response handler after validating only the generic 24-byte three-address 802.11 header.

2

What must an attacker provide to trigger the out-of-bounds read?

An attacker must cause a malformed association response shorter than the 30-byte fixed association-response prefix to be processed. The undersized frame causes the information-element length calculation to wrap and lets the parser read beyond the receive buffer.

3

How can the issue be mitigated if the fix cannot be applied immediately?

The provided data does not identify a configuration workaround. Reducing exposure to untrusted wireless management traffic on affected ipw2100 or ipw2200 devices may limit opportunities to supply malformed association responses.

4

How can I determine whether a system is affected?

Check whether the running Linux kernel includes the referenced stable fixes and whether the system uses an ipw2100 or ipw2200 device path relying on libipw. The supplied data does not provide affected or fixed kernel version numbers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203