Sceawere

Vulnerability Detail

CVE-2026-98348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libipw Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: reject too-short association responses libipw_handle_assoc_resp() reads the capability, status and aid fields of the 30-byte association response prefix and then computes the information element length as stats->len - sizeof(*frame) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() turns a frame shorter than the fixed fields into a length near 64 KiB, and the parser then reads past the receive buffer. Both the ipw2100 and ipw2200 management receive paths reach this function having established only that the frame carries the generic 24-byte three-address header. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:18:27.963Z",
  "pubdate": "2026-10-06T09:18:27.963Z",
  "executiveSummary": "A critical out-of-bounds read vulnerability exists in the Linux kernel's libipw library, specifically within the association response handling logic. The issue arises from improper length validation during the processing of management frames.\nThe vulnerability is triggered when the kernel receives a maliciously crafted association response frame that is shorter than the expected fixed-field length. This lack of validation leads to an integer underflow during length arithmetic, which subsequently forces a large, incorrect length value to be passed to the information element parser.\nThis flaw affects devices utilizing ipw2100 and ipw2200 drivers. An unauthenticated remote attacker within radio range can exploit this by injecting a malformed management frame, potentially resulting in memory corruption, kernel information disclosure, or system instability.\nThe impact is significant as it allows for an out-of-bounds memory access, potentially exposing sensitive kernel memory or causing a denial-of-service condition via a kernel panic. No specific user privileges are required for exploitation as the vulnerability resides in the packet processing path of the wireless stack, making it reachable by any attacker capable of transmitting malformed frames over the air to a vulnerable wireless interface.",
  "technicalDetails": "The vulnerability is located in the libipw_handle_assoc_resp() function, which is responsible for parsing association response frames. The function is designed to process a 30-byte association response prefix containing mandatory fields such as capability, status, and Association ID (AID).\nThe root cause is an integer underflow vulnerability during the calculation of the remaining buffer length. The code performs the calculation: stats->len - sizeof(*frame). Here, 'stats->len' is a u16 (unsigned 16-bit integer), while 'sizeof(*frame)' is a size_t. When the actual frame size is smaller than the expected 'sizeof(*frame)', the subtraction does not result in a negative number; instead, due to the type promotion to size_t, the result wraps around to a very large value (near 64 KiB).\nThis erroneously large value is subsequently passed as a length parameter to libipw_parse_info_param(). Because the parser believes there is significantly more data to process than actually exists in the received buffer, it performs reads past the bounds of the allocated receive buffer. This leads to an out-of-bounds read of kernel memory.\nThe attack flow proceeds as follows: 1) An attacker crafts a malicious 802.11 association response frame with a length significantly shorter than the expected 30-byte fixed header. 2) The frame is transmitted to the target device. 3) The ipw2100/ipw2200 drivers pass the frame to libipw_handle_assoc_resp() after validating only the generic 24-byte three-address header. 4) The function performs the flawed arithmetic, calculating a massive length parameter. 5) The libipw_parse_info_param() function interprets this length and proceeds to copy or parse data from memory addresses immediately following the receive buffer.\nThe exploitation allows an attacker to cause the kernel to access unauthorized memory segments. Depending on the environment, this can be leveraged to leak kernel pointers or internal structures (information disclosure) or crash the kernel when the read operation crosses a page boundary or touches unmapped memory (DoS). The vulnerability is particularly dangerous because it occurs early in the frame processing stage, requiring no prior authentication or association between the attacker and the victim device."
}
CVE-2026-98348: libipw Out-of-Bounds Read Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere