Linux Kernel Vulnerability in WiFi Module Affecting Multiple Devices
CVE-2026-98349

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98349?

A vulnerability has been identified within the Linux kernel's WiFi module, specifically in how it processes management frames. The functions responsible for handling beacon and probe responses fail to adequately validate the length of incoming frames. When a management frame is received, the system erroneously computes the length based on a fixed header size, which may lead to reading beyond the allocated memory of the buffer. This can potentially allow malicious users to manipulate the system by sending specifically crafted frames, possibly leading to denial of service or other unforeseen behaviors. Developers are advised to implement proper validation mechanisms to reject malformed frames before processing any fixed fields to mitigate this risk.

Affected Version(s)

Linux b453872c35cfcbdbf5a794737817f7d4e7b1b579

Linux b453872c35cfcbdbf5a794737817f7d4e7b1b579 < 23afeb5d2bdfd34c8a0a661876291a4fa9978293

Linux b453872c35cfcbdbf5a794737817f7d4e7b1b579 < 89959ff00a978f3172726d3d5f861ee6f1aae26d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.