In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
The KASAN allocation trace shows that a malformed IE buffer is stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any validation. The crash trace shows that a subsequent SIOCSIWESSID triggers a connection attempt which calls cfg80211_sme_get_conn_ies() to process the stored IE buffer, causing:
-
An out-of-bounds read in skip_ie() which reads ies[pos+1] (the length byte) past the end of the 1-byte buffer.
-
An integer underflow in the memcpy size argument when offs returned by ieee80211_ie_split() exceeds ies_len, causing unsigned subtraction to wrap to SIZE_MAX and triggering a fortify panic.
Fix this by validating the IE buffer in cfg80211_wext_siwgenie() before storing it.
[drop unnecessary ie_len check, update commit message]
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93784
- https://git.kernel.org/stable/c/01cc395cecfaa73134d39fb9a401d9605d8bb2c5
- https://git.kernel.org/stable/c/a2f5286ca4f304d3fd469f01b96b518608912a5c
- https://git.kernel.org/stable/c/c970879e03b23a27df42caf7ba506485a165fb96
- https://git.kernel.org/stable/c/269498ce6c1e2132b072aa0c8660404926008f03
- https://git.kernel.org/stable/c/685082f4be77f4657b498ebbe9f942ef65c492cf
- https://git.kernel.org/stable/c/8b921a8993469a3482e0c67b5ce5cb6ce93f5f61
- https://git.kernel.org/stable/c/d01f1600e8b075aa17adb751ac9881bb6ee40dcc
- https://github.com/advisories/GHSA-j7q2-v7q5-76jp