Out-of-bounds write in Linux kernel - CVE-2026-97518
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause memory corruption.
The vulnerability exists due to improper validation of duplicate cipher suite entries in cfg80211 wiphy registration when WEXT compatibility code handles SIOCGIWRANGE requests. A local privileged user can register a wiphy with duplicate WEP cipher suite entries and request wireless range information to cause memory corruption.