In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.
Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.
Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: avoid out-of-bounds read for empty PREQ elements ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom fields before checking whether the element contains even the fixed header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to account for the optional Address Extension field. Consequently, an empty PREQ element causes a one-byte read beyond its declared payload. Move the helper call after both size checks, so the bottom fields are only accessed when they are present. | |
| Title | wifi: mac80211: avoid out-of-bounds read for empty PREQ elements | |
| First Time appeared |
Linux
Linux linux Kernel |
|
| CPEs | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linux
Linux linux Kernel |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2026-10-06T08:44:26.024Z
Reserved: 2026-09-25T10:25:14.323Z
Link: CVE-2026-98183
No data.
Status : Received
Published: 2026-10-06T09:18:03.103
Modified: 2026-10-06T09:18:03.103
Link: CVE-2026-98183
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.