Heap-Based Buffer Overflow in Morse Micro HaLowLink 2 Wi-Fi Driver
CVE-2026-7762
What is CVE-2026-7762?
A heap-based buffer overflow vulnerability exists in the dot11ah.ko HaLow Wi-Fi kernel driver of Morse Micro's HaLowLink 2 software. This flaw enables an unauthenticated attacker within radio range to potentially cause a Denial of Service (kernel panic) or achieve Remote Code Execution. By sending a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information Element, attackers can exploit a mismanaged memory buffer. The specific function, morse_dot11ah_find_s1g_caps_for_bssid(), fails to validate the size of the memory being copied, allowing attackers to supply excessive data, leading to severe implications in the kernel heap memory. This vulnerability can be triggered during normal operation, without requiring authentication or user interaction.
Affected Version(s)
HaLowLink 2 0 < 2.11.13
