CVE-2026-98349: wifi: libipw: reject too-short beacon and probe responses

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: libipw: reject too-short beacon and probe responses

libipwprocessproberesponse() and the libipwnetworkinit() call it makes assume the frame contains the full 36-byte beacon and probe response prefix, but the ipw2100 and ipw2200 receive paths only establish that a management frame carries the generic 24-byte three-address header.

libipwnetworkinit() then computes the information element length as

stats->len - sizeof(beacon)

stats->len is a u16 and sizeof() has type sizet, so the subtraction is evaluated as sizet and wraps instead of going negative. Truncating that to the u16 length parameter of libipwparseinfoparam() yields 65524 for a 24-byte beacon, and the parser then walks the receive buffer as if it held almost 64 KiB of information elements, reading past the allocation.

Reject the frame before any fixed field is touched.

Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.

Affected Software

1 affected component
Linux Linux kernel libipw

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the libipw management-frame receive path, reject too-short beacon and probe response frames before accessing any fixed fields, ensuring the frame contains the full expected 36-byte beacon/probe response prefix.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203