Answer in brief
CVE-2026-68351 records a Unknown severity vulnerability in wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <f74e34e66379e487a09009a4f2d42470051672bd || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <500c36649f270de05a56591fcc1aaaa36687958e || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <9aee949c68dc6dccbc54333537b109c53fe2079f || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <cb7a38810cf25738176dac32dec7a146b3f959cf || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <4cde55b2feff9504d1f993ab80e84e7ccb62791c | f74e34e66379e487a09009a4f2d42470051672bd, 500c36649f270de05a56591fcc1aaaa36687958e, 9aee949c68dc6dccbc54333537b109c53fe2079f, cb7a38810cf25738176dac32dec7a146b3f959cf, 4cde55b2feff9504d1f993ab80e84e7ccb62791c |
| Linux/Linuxgeneric | 2.6.37 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar->readlen, this copies more data than the readbuf was allocated for. Bound the memcpy to min(len - 4, ar->readlen) so that the response is still completed -- avoiding repeated restarts from queued garbage -- while preventing an overread past the response buffer.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68351 records a Unknown severity vulnerability in wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <f74e34e66379e487a09009a4f2d42470051672bd || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <500c36649f270de05a56591fcc1aaaa36687958e || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <9aee949c68dc6dccbc54333537b109c53fe2079f || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <cb7a38810cf25738176dac32dec7a146b3f959cf || >=a84fab3cbfdc427e7d366f1cc844f27b2084c26c <4cde55b2feff9504d1f993ab80e84e7ccb62791c | f74e34e66379e487a09009a4f2d42470051672bd, 500c36649f270de05a56591fcc1aaaa36687958e, 9aee949c68dc6dccbc54333537b109c53fe2079f, cb7a38810cf25738176dac32dec7a146b3f959cf, 4cde55b2feff9504d1f993ab80e84e7ccb62791c |
| Linux/Linuxgeneric | 2.6.37 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar->readlen, this copies more data than the readbuf was allocated for. Bound the memcpy to min(len - 4, ar->readlen) so that the response is still completed -- avoiding repeated restarts from queued garbage -- while preventing an overread past the response buffer.
Quoted source text, attributed separately from HOL analysis.