HIGH Introduced in 5.7
wilc1000 P2PFrame OOB
CVE-2026-98190
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix out-of-bounds read in P2P public action frames wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once ieee80211_is_public_action() returns true. That helper only verifies the frame is long enough for the action category field, that is offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both functions then read the P2P public action header up to oui_subtype at offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32. A public action frame of 25 to 31 bytes passes the check but is shorter than that 32 byte header, so oui_subtype can be read out of bounds, and because the length is unsigned, "size - ie_offset" underflows to a value close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length, so even the size_t subtraction in mgmt_tx() is truncated to the same value. It then walks far past the buffer searching for a vendor element until it reaches unmapped memory. In the receive path the frame arrives over the air and needs no association, so a nearby unauthenticated device can crash the host while it is in P2P listen. Reject frames shorter than the P2P public action header in both paths before dereferencing it.
02KernelScan AI Analysis
Risk summary
A nearby unauthenticated device can send a short Wi-Fi Direct (P2P) public action frame to a host using the Microchip wilc1000 Wi-Fi chip while it is in P2P listen state. The driver mis-validates the frame length and then scans up to ~4 GiB past the end of the frame buffer, causing a kernel crash when it walks into unmapped memory. No association or credentials are needed, so any device within radio range can trigger the denial of service.
Vulnerability analysis
The wilc1000 Wi-Fi driver begins parsing received and transmitted Wi-Fi Direct public action frames after only checking that the frame is long enough to contain the action category byte, but it then reads a larger P2P-specific header and computes the remaining frame length as an unsigned subtraction. A frame that is a few bytes too short passes the initial check, so the driver reads past the end of the buffer, and the length calculation underflows to a value near 4 GiB, making the driver scan far beyond the buffer until it hits unmapped memory and crashes the kernel. The fix rejects any frame shorter than the full P2P public action header before the header is read or the length is computed, in both the receive and transmit paths. The receive path is reachable over the air with no association or authentication, so an attacker only needs to be within radio range of a device using this Wi-Fi chip while its P2P interface is listening; the transmit path additionally requires local access to the wireless configuration interface.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 5.7 | 5.10.271 | e98ad9f4c59f |
| 5.15 | 5.7 | 5.15.222 | f0c46f8111a4 |
| 6.1 | 5.7 | 6.1.189 | a5b827dad8a3 |
| 6.6 | 5.7 | 6.6.158 | 491df93b10d7 |
| 6.12 | 5.7 | 6.12.112 | cc2ee642ebea |
| 6.18 | 5.7 | 6.18.54 | 68b786691ce2 |
| 7.2 | 5.7 | 7.2.8 | 6fbe76eb2796 |
| mainline | 5.7 | 7.3-rc4 | ba6cb7c0868a |