Kernel Vulnerability in Linux Affecting Wi-Fi Modules from Intel
CVE-2026-98348

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98348?

A vulnerability exists in the Linux kernel where the libipw module inadequately handles too-short association responses in Wi-Fi communications. In the function libipw_handle_assoc_resp(), the processing of the 30-byte association response can lead to an incorrect computation of the information element length. This flaw allows for a situation where the frame length is misinterpreted, potentially resulting in a buffer overflow and reading past the allocated buffer. Specifically, the function fails to reject frames that do not conform to expected lengths prior to examining fixed fields, making it susceptible to unintended memory access. This issue was identified during an AI-assisted code review and verified through KUnit tests on an emulated environment.

Affected Version(s)

Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 766268b429ae26d8ca599031fa962b0fe4673120

Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6

Linux 9e8571affd1c54b9638b4ff9844e47aae07310f6 < 400b89217058fac672134a0d4092c8493dadb8ad

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.