Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-98183
CVE-2026-98183
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom fields before checking whether the element contains even the fixed header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to account for the optional Address Extension field. Consequently, an empty PREQ element causes a one-byte read beyond its declared payload.
Move the helper call after both size checks, so the bottom fields are only accessed when they are present.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.