VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-98183

CVE-2026-98183

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: avoid out-of-bounds read for empty PREQ elements

ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom fields before checking whether the element contains even the fixed header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to account for the optional Address Extension field. Consequently, an empty PREQ element causes a one-byte read beyond its declared payload.

Move the helper call after both size checks, so the bottom fields are only accessed when they are present.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.