CVE-2026-97518
CVE CVE-2026-97518EUVD EUVD-2026-86116Published 2026-09-24T16:05:18.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject duplicate wiphy cipher suite entries Duplicate entries in wiphy->cipher_suites do not describe any additional capability, but cfg80211 currently accepts them and leaves individual consumers to deal with them. One such consumer is the WEXT compatibility code, which appends a WEP key length for each WEP cipher entry it sees. Repeated WEP entries can therefore overflow the fixed iw_range::encoding_size array returned by SIOCGIWRANGE. Reject duplicate cipher suite entries in wiphy_register() instead. This keeps the cipher suite invariant in one place and makes malformed wiphy descriptions fail early with -EINVAL, rather than relying on a single cfg80211 user to handle duplicates correctly.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <4cbb2360f4d8c29e67bc7a8bf6ba0ae096583923; patch: 7.2; patch: 6.12.111; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1305f8b925fe92edf5fec183588dfc7db719180b; 0 <6.18.53; patch: 6.18.53; 0 <6.12.111; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7187d145d9042b037e4f10538f70cf95e380219f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.