Answer in brief
CVE-2026-98190 records a Unknown severity vulnerability in wifi: wilc1000: fix out-of-bounds read in P2P public action frames. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <e98ad9f4c59f2e836f8d971b57763a4277680422 || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <f0c46f8111a479b97b8ab17747c528cade6257f1 || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <a5b827dad8a3037cef04d0240d1c2acb1557101e || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <491df93b10d76aebaf6aa4bb05a6ba897f4fccfb || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <cc2ee642ebeac8699b671ddb6d5955a785e5ff43 || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <68b786691ce24c5c94e28811db243e573c50f9c1 || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304 || >=4fb8b5aa2a1126783ae00bae544d6f3c519408ef <ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 | e98ad9f4c59f2e836f8d971b57763a4277680422, f0c46f8111a479b97b8ab17747c528cade6257f1, a5b827dad8a3037cef04d0240d1c2acb1557101e, 491df93b10d76aebaf6aa4bb05a6ba897f4fccfb, cc2ee642ebeac8699b671ddb6d5955a785e5ff43, 68b786691ce24c5c94e28811db243e573c50f9c1, 6fbe76eb2796d2aee45cc6a2dd16e85d3cc96304, ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 |
| Linux/Linuxgeneric | 5.7 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32. A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory. In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
Quoted source text, attributed separately from HOL analysis.