CVE-2026-98188 (GCVE-0-2026-98188)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:44 – Updated: 2026-10-06 08:44
VLAI
Title
wifi: p54: validate curve data length in the calibration curve converters
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate curve data length in the calibration curve converters p54_convert_rev0() and p54_convert_rev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54_convert_output_limits() and p54_convert_db() already validate their counts against the entry length; this path was missed. Reject the entry when the counts do not fit in the entry data.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 81084c967c18233b19799a0c3352ebac043f31e2 (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 41cdf14bf4b52fbe4673a172c2a6ad756cb08111 (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 03d313e3dfb49a44c10a5c423452967694fb85e2 (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 42f4b03971f9d6329c4cbd1ea5155210d16ab65b (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 4d767d6f8753db22bfc14c2724bd9cee677ffb03 (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < 3bdcc4d61212b001b8752d80036509b4974ce16c (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < b0c906107150b16925ee66da09127259864c7f36 (git)
Affected: eff1a59c48e3c6a006eb4fe5f2e405a996f2259d , < ce858fa6b8a214dee5adb82358885fa024cdd887 (git)
Create a notification for this product.
Linux Linux Affected: 2.6.24
Unaffected: 0 , < 2.6.24 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/intersil/p54/eeprom.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "81084c967c18233b19799a0c3352ebac043f31e2",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "41cdf14bf4b52fbe4673a172c2a6ad756cb08111",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "03d313e3dfb49a44c10a5c423452967694fb85e2",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "42f4b03971f9d6329c4cbd1ea5155210d16ab65b",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "4d767d6f8753db22bfc14c2724bd9cee677ffb03",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "3bdcc4d61212b001b8752d80036509b4974ce16c",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "b0c906107150b16925ee66da09127259864c7f36",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            },
            {
              "lessThan": "ce858fa6b8a214dee5adb82358885fa024cdd887",
              "status": "affected",
              "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/intersil/p54/eeprom.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.24"
            },
            {
              "lessThan": "2.6.24",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "2.6.24",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate curve data length in the calibration curve converters\n\np54_convert_rev0() and p54_convert_rev1() read calibration curve\ndata from the device-supplied EEPROM entry using channel and\npoints-per-channel counts taken verbatim from that same entry, so\nan entry that declares more data than it carries drives an\nout-of-bounds read past the EEPROM buffer (verified with a KASAN\nreproducer of the conversion loop). The sibling converters\np54_convert_output_limits() and p54_convert_db() already validate\ntheir counts against the entry length; this path was missed.\n\nReject the entry when the counts do not fit in the entry data."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:44:30.096Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/81084c967c18233b19799a0c3352ebac043f31e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/41cdf14bf4b52fbe4673a172c2a6ad756cb08111"
        },
        {
          "url": "https://git.kernel.org/stable/c/03d313e3dfb49a44c10a5c423452967694fb85e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/42f4b03971f9d6329c4cbd1ea5155210d16ab65b"
        },
        {
          "url": "https://git.kernel.org/stable/c/4d767d6f8753db22bfc14c2724bd9cee677ffb03"
        },
        {
          "url": "https://git.kernel.org/stable/c/3bdcc4d61212b001b8752d80036509b4974ce16c"
        },
        {
          "url": "https://git.kernel.org/stable/c/b0c906107150b16925ee66da09127259864c7f36"
        },
        {
          "url": "https://git.kernel.org/stable/c/ce858fa6b8a214dee5adb82358885fa024cdd887"
        }
      ],
      "title": "wifi: p54: validate curve data length in the calibration curve converters",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98188",
    "datePublished": "2026-10-06T08:44:30.096Z",
    "dateReserved": "2026-09-25T10:25:14.323Z",
    "dateUpdated": "2026-10-06T08:44:30.096Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98188",
      "date": "2026-10-08",
      "epss": "0.00176",
      "percentile": "0.06592"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/wireless/intersil/p54/eeprom.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "81084c967c18233b19799a0c3352ebac043f31e2",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "41cdf14bf4b52fbe4673a172c2a6ad756cb08111",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "03d313e3dfb49a44c10a5c423452967694fb85e2",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "42f4b03971f9d6329c4cbd1ea5155210d16ab65b",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4d767d6f8753db22bfc14c2724bd9cee677ffb03",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "3bdcc4d61212b001b8752d80036509b4974ce16c",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b0c906107150b16925ee66da09127259864c7f36",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ce858fa6b8a214dee5adb82358885fa024cdd887",
                    "status": "affected",
                    "version": "eff1a59c48e3c6a006eb4fe5f2e405a996f2259d",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/wireless/intersil/p54/eeprom.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.6.24"
                  },
                  {
                    "lessThan": "2.6.24",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate curve data length in the calibration curve converters\n\np54_convert_rev0() and p54_convert_rev1() read calibration curve\ndata from the device-supplied EEPROM entry using channel and\npoints-per-channel counts taken verbatim from that same entry, so\nan entry that declares more data than it carries drives an\nout-of-bounds read past the EEPROM buffer (verified with a KASAN\nreproducer of the conversion loop). The sibling converters\np54_convert_output_limits() and p54_convert_db() already validate\ntheir counts against the entry length; this path was missed.\n\nReject the entry when the counts do not fit in the entry data."
          }
        ],
        "id": "CVE-2026-98188",
        "lastModified": "2026-10-06T09:18:03.867",
        "metrics": {},
        "published": "2026-10-06T09:18:03.867",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/03d313e3dfb49a44c10a5c423452967694fb85e2"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/3bdcc4d61212b001b8752d80036509b4974ce16c"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/41cdf14bf4b52fbe4673a172c2a6ad756cb08111"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/42f4b03971f9d6329c4cbd1ea5155210d16ab65b"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/4d767d6f8753db22bfc14c2724bd9cee677ffb03"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/81084c967c18233b19799a0c3352ebac043f31e2"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b0c906107150b16925ee66da09127259864c7f36"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ce858fa6b8a214dee5adb82358885fa024cdd887"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "redhat_vex": {
      "aggregate_severity": "Moderate",
      "current_release_date": "2026-10-08T23:35:26+00:00",
      "cve": "CVE-2026-98188",
      "id": "CVE-2026-98188",
      "initial_release_date": "2026-10-06T00:00:00+00:00",
      "product_status:known_not_affected": "277",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "kernel: wifi: p54: validate curve data length in the calibration curve converters",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98188.json",
      "version": "3"
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:51:09Z",
      "cve": "CVE-2026-98188",
      "id": "CVE-2026-98188",
      "initial_release_date": "2026-10-08T16:51:09Z",
      "product_status:known_affected": "301",
      "product_status:known_not_affected": "46",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98188",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98188.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…