KernelScan.io

HIGH Introduced in 3.0

mwifiex ScanResponse OOB

CVE-2026-98185

CVSS 8.7 / 10.0 KernelScan AI

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: validate scan response extents mwifiex_ret_802_11_scan() subtracts the fixed response fields and the firmware-provided BSS length from resp->size without first proving that either extent fits. A short response or oversized BSS length can therefore underflow tlv_buf_size and make the TLV parser walk beyond the command response. Compute the fixed extent from the selected normal or background scan response. Validate that the fixed fields and BSS data fit before deriving the TLV extent and entering the parser.

02

Engine v0.7.0

Risk summary

Devices with Marvell mwifiex WiFi chipsets are vulnerable to out-of-bounds memory access when processing scan responses. A malicious access point within WiFi range can send crafted frames that cause the firmware to produce a malformed scan response, leading to kernel memory corruption or crash. No user interaction or privileges on the target device are required.

Affecteddrivers/net/wireless/marvell/mwifiex/scan.c (mwifiex WiFi driver)

Vulnerability analysis

The mwifiex WiFi driver computes the size of the TLV buffer in a firmware scan response by subtracting the fixed response header and the firmware-reported BSS description length from the total response size. When the firmware supplies a short response or an oversized BSS length, this unsigned subtraction underflows, producing a very large TLV buffer extent that causes the TLV parser to walk far beyond the actual command response buffer. The fix computes the fixed-field extent from the actual response structure, validates that both the fixed fields and BSS data fit within the response before deriving the TLV extent, and rejects responses that fail these checks. This vulnerability is reachable over WiFi: a malicious access point within radio range can send crafted beacon or probe response frames that cause the firmware to generate a malformed scan response, which the driver then processes during a routine WiFi scan. No privileges or user interaction on the target device are required—only that the device has a Marvell mwifiex WiFi chipset and performs scanning.

03

BranchIntroducedFixed inPatch commit
5.103.05.10.27125217c5f6ce0
5.153.05.15.22248312f0085aa
6.13.06.1.189dccf5ecaad4d
6.63.06.6.158c4943323fda2
6.123.06.12.112cb0008480ed7
6.183.06.18.549cff2f39ed38
7.23.07.2.87106ad8b74f5
mainline3.07.3-rc43687d7d48070