In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: phy: check length before parsing PHY status IE
Hardware might report PHY status IE with unexpected length, and parser might access out of range. Check the length ahead.
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: phy: check length before parsing PHY status IE
Hardware might report PHY status IE with unexpected length, and parser might access out of range. Check the length ahead.
September 24, 2026
October 3, 2026
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.1.106-1 ... 7.2~rc7-1~exp1 (360 versions) |
| — |
| linux-6.12 | 6.12.100-1~deb12u1, 6.12.101-1~deb12u1, 6.12.107-1~deb12u1 |
| — |
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 6.12.96-1 (35 versions) |
| — |
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 7.2~rc7-1~exp1 (179 versions) |
| — |
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-97500
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.