HIGH Introduced in 3.0
mwifiex PairwiseCipher OOB
CVE-2026-98186
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a beacon/probe-response RSN or WPA information element and then walks that many 4-byte OUIs, comparing each with memcmp(). The count comes straight from the (attacker-supplied) IE and is never checked against the element's own length, and the callers admit the element on element_id alone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted RSN/WPA IE with a large pairwise count therefore makes the walk read up to 255 * 4 bytes past the element -- an out-of-bounds read of the kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe response is processed during scan-result parsing. Pass the number of IE bytes available at the OUI list and bound the walk to the element. Keep the length signed and reject a negative value before any unsigned arithmetic, so a small or zero IE length cannot underflow to a large size_t and defeat the bound. Found by 0sec automated security-research tooling (https://0sec.ai).
02KernelScan AI Analysis
Risk summary
Any device using a Marvell mwifiex WiFi chipset that processes scan results is vulnerable to a kernel out-of-bounds read triggered by a nearby attacker crafting a beacon or probe-response with an inflated pairwise-cipher count. The read can access up to a kilobyte past the element boundary in kernel heap memory, potentially leaking sensitive data or causing a kernel panic. No authentication or user interaction is required — the device need only be within WiFi range and actively scanning.
Vulnerability analysis
The mwifiex WiFi driver parses RSN/WPA information elements from beacon and probe-response frames during scan-result processing. A pairwise-cipher count field inside the element is read directly from the frame and used to walk that many 4-byte OUI entries, but the count is never checked against the element's actual length. A nearby attacker can craft a beacon or probe-response with an inflated pairwise-cipher count, causing the driver to read up to a thousand bytes past the element boundary in a kernel heap buffer. The fix passes the available element length into the OUI search function and bounds the walk to it, also guarding against integer underflow when the length is small or zero. Any device using a Marvell mwifiex WiFi chipset that processes scan results is reachable by an attacker within WiFi range, with no authentication or user interaction required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 3.0 | 5.10.271 | 77e642af7f2f |
| 5.15 | 3.0 | 5.15.222 | 982b8fcdbb28 |
| 6.1 | 3.0 | 6.1.189 | 58767b41f872 |
| 6.6 | 3.0 | 6.6.158 | 2402c9e2644b |
| 6.12 | 3.0 | 6.12.112 | 54a9cc5bd70b |
| 6.18 | 3.0 | 6.18.54 | 8bbef2b1ebfb |
| 7.2 | 3.0 | 7.2.8 | 46cda9d42f0d |
| mainline | 3.0 | 7.3-rc4 | e667aee1c192 |