Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: wilc1000: fix out-of-bounds read in P2P public action frames

wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
ieee80211_is_public_action() returns true. That helper only verifies the
frame is long enough for the action category field, that is
offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both
functions then read the P2P public action header up to oui_subtype at
offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where
ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.

A public action frame of 25 to 31 bytes passes the check but is shorter
than that 32 byte header, so oui_subtype can be read out of bounds, and
because the length is unsigned, "size - ie_offset" underflows to a value
close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,
so even the size_t subtraction in mgmt_tx() is truncated to the same
value. It then walks far past the buffer searching for a vendor element
until it reaches unmapped memory.

In the receive path the frame arrives over the air and needs no
association, so a nearby unauthenticated device can crash the host while
it is in P2P listen. Reject frames shorter than the P2P public action
header in both paths before dereferencing it.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via out-of-bounds read
Action: Immediate Patch
AI Analysis

Impact

The vulnerable code exists in the Linux wilc1000 Wi‑Fi driver. When the driver parses a P2P public action frame that is only 25 to 31 bytes long, it fails to verify the frame meets the 32‑byte header length. The code then reads the oui_subtype field out of bounds, and a size underflow causes an over‑sized search buffer that walks into unmapped memory. This results in a kernel panic and a system reboot or loss of service. The weakness is a classic buffer read overflow that can crash the host.

Affected Systems

All Linux kernels that include the wilc1000 driver before the patch commit. The fix addresses the driver in the mainline kernel; any distribution using a pre‑patched kernel is affected. No specific LTS version is singled out, so all up‑to‑date kernels after the patch are safe.

Risk and Exploitability

A nearby unauthenticated wireless device can send a crafted 25‑31 byte P2P action frame to a host in P2P listen mode, triggering the crash. The exploit requires only local wireless proximity and no authentication, making it low effort but potentially high impact for the host. EPSS data is not available and the vulnerability is not listed in the KEV catalog, but the attack scenario is straightforward and the consequences are significant for an affected device.

Generated by OpenCVE AI on October 6, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel version that includes the wilc1000 patch (commit 491df93b10d76aebaf6aa4bb05a6ba897f4fccfb).
  • Rebuild embedded firmware or custom kernel images to incorporate the patched wilc1000 driver when a direct kernel upgrade is not feasible.
  • If an immediate kernel upgrade is impossible, disable the wilc1000 wireless interface or turn off P2P mode to prevent receipt of malicious frames while a patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32. A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory. In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
Title wifi: wilc1000: fix out-of-bounds read in P2P public action frames
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:44:31.520Z

Reserved: 2026-09-25T10:25:14.323Z

Link: CVE-2026-98190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:04.210

Modified: 2026-10-06T09:18:04.210

Link: CVE-2026-98190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:30:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer