Out-of-bounds read in Linux kernel - CVE-2026-97500
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to improper length validation in the rtw89 PHY status information element parser when processing PHY status information elements with unexpected lengths. A remote attacker can cause the parser to process a PHY status information element with an unexpected length to cause an out-of-bounds read.