CVE-2026-98183

EUVD-2026-93111
In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: avoid out-of-bounds read for empty PREQ elements

ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.

Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.84%
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.176-1
fixed
bookworm (security)
6.1.187-1
fixed
forky
7.2.8-1
fixed
sid
7.2.9-1
fixed
trixie
6.12.107-1
fixed
trixie (security)
6.12.111-1
fixed