CVE-2026-98183 PUBLISHED

wifi: mac80211: avoid out-of-bounds read for empty PREQ elements

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: avoid out-of-bounds read for empty PREQ elements

ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom fields before checking whether the element contains even the fixed header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to account for the optional Address Extension field. Consequently, an empty PREQ element causes a one-byte read beyond its declared payload.

Move the helper call after both size checks, so the bottom fields are only accessed when they are present.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8b40b1d24a6099fe9fac8e207d4cb04ab5e0baae to 3beddbd56946577478fd5e649f556aaaebe15b0a (excl.)
  • affected from 8b40b1d24a6099fe9fac8e207d4cb04ab5e0baae to e6031f02269c0f51cf67886d177f02bc300b47cd (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.2 is affected
  • unaffected from 0 to 7.2 (excl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References