{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "9e8571affd1c54b9638b4ff9844e47aae07310f6"
            },
            {
              "fixed": "766268b429ae26d8ca599031fa962b0fe4673120"
            },
            {
              "fixed": "d70bdb84cf1782039384c1ffa7a18b0303c286a7"
            },
            {
              "fixed": "400b89217058fac672134a0d4092c8493dadb8ad"
            },
            {
              "fixed": "46aa75291056b6dc5faaf956dffdb3e9662477b0"
            },
            {
              "fixed": "e3025ecdb2057f866c09e059fc1466e81d6f243e"
            },
            {
              "fixed": "14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb"
            },
            {
              "fixed": "af1b69be19c34e28c0ae54bee954b58cd076969a"
            },
            {
              "fixed": "adb7118b7d2cfd7e8213c17d7d2829f353017754"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.6.15"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.222"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98348.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libipw: reject too-short association responses\n\nlibipw_handle_assoc_resp() reads the capability, status and aid fields\nof the 30-byte association response prefix and then computes the\ninformation element length as\n\n\tstats-\u003elen - sizeof(*frame)\n\nstats-\u003elen is a u16 and sizeof() has type size_t, so the subtraction is\nevaluated as size_t and wraps instead of going negative.  Truncating\nthat to the u16 length parameter of libipw_parse_info_param() turns a\nframe shorter than the fixed fields into a length near 64 KiB, and the\nparser then reads past the receive buffer.\n\nBoth the ipw2100 and ipw2200 management receive paths reach this\nfunction having established only that the frame carries the generic\n24-byte three-address header.\n\nReject the frame before any fixed field is touched.\n\nFound by an AI-assisted review of length arithmetic in management frame\nparsers.  Verified with a KUnit case under Generic KASAN on arm64 under\nQEMU; I do not have the hardware, so it is not tested on a real device.",
  "id": "CVE-2026-98348",
  "modified": "2026-10-08T02:30:33.390126086Z",
  "published": "2026-10-06T08:46:36.927Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/14cb425ba1f3a5d849e3bbc3d02d84e0ae195dbb"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/400b89217058fac672134a0d4092c8493dadb8ad"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/46aa75291056b6dc5faaf956dffdb3e9662477b0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/766268b429ae26d8ca599031fa962b0fe4673120"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/adb7118b7d2cfd7e8213c17d7d2829f353017754"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/af1b69be19c34e28c0ae54bee954b58cd076969a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d70bdb84cf1782039384c1ffa7a18b0303c286a7"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e3025ecdb2057f866c09e059fc1466e81d6f243e"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98348.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98348"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "wifi: libipw: reject too-short association responses"
}