CVE-2026-68196
CVE CVE-2026-68196EUVD EUVD-2026-55297Published 2026-08-10T12:00:14.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: validate assoc response length before subtracting header wilc_parse_assoc_resp_info() computes the trailing IE length as ies_len = buffer_len - sizeof(*res); without first checking that buffer_len is at least sizeof(struct wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a received association response (host_int_parse_assoc_resp_info() passes hif_drv->assoc_resp / assoc_resp_info_len straight in) and must be validated before the driver accesses the fixed header. For a frame shorter than the 6-byte fixed header, the subtraction wraps. For a four-byte response the result is truncated to a u16 ies_len of 65534, so kmemdup() then attempts to copy 65534 bytes starting at buffer + sizeof(*res), beyond the valid association-response data (CWE-125). A response shorter than four bytes can also cause an out-of-bounds read of res->status_code at offsets 2 and 3. Reject frames too short to hold the fixed header before touching the header or computing ies_len. Also set the connection status to a failure on this path: the caller falls through to a "conn_info->status == WLAN_STATUS_SUCCESS" check after the parser returns, so leaving the status untouched could let a malformed short response be treated as a successful association.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4.2; patch: 6.6.148; patch: 6.18.42; patch: 0; c5c77ba18ea66aa05441c71e38473efb787705a4 <e511e93abd6eeedcd5b3c55516241f414fbde64a; c5c77ba18ea66aa05441c71e38473efb787705a4 <4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de; patch: 7.1.6; c5c77ba18ea66aa05441c71e38473efb787705a4 <8ccdf8c8de87a9580df37c3c1ec53ba88cedef65; patch: 6.12.101; c5c77ba18ea66aa05441c71e38473efb787705a4 <584c8954ad55f8b09b475be6db710fe40ceb988c; patch: 7.2-rc5; c5c77ba18ea66aa05441c71e38473efb787705a4 <4d410320e8ae5933e651660c9fadc1d380309e23
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.