Heap-based Buffer Overflow in Morse Micro HaLowLink 2 Software
CVE-2026-7763

9.8CRITICAL

Key Information:

Vendor
CVE Published:
5 June 2026

What is CVE-2026-7763?

A heap-based buffer overflow vulnerability exists in the morse.ko HaLow Wi-Fi kernel driver of Morse Micro's HaLowLink 2 software versions earlier than 2.11.13. This flaw allows an unauthenticated attacker within radio range to exploit a crafted 802.11ah beacon frame, leading to a potential Denial of Service (DoS) via kernel panic or even enabling remote code execution. The vulnerability arises from the morse_page_slicing_process_tim_element() function in page_slicing.c, which fails to validate the TIM bitmap length before writing to a fixed-size destination buffer, permitting the attacker to overflow the buffer by up to 252 bytes. Since beacons are processed during passive scanning without authentication or user interaction, the risk of exploitation is significantly heightened.

Affected Version(s)

HaLowLink 2 0 < 2.11.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.