CVE-2026-74341

high

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.

References

https://git.kernel.org/stable/c/dae9cadf0925f1cbfb71306d60490890df3870a6

https://git.kernel.org/stable/c/cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92

https://git.kernel.org/stable/c/88a240d86d3d64521f9194abe185ac71cc74d0bd

https://git.kernel.org/stable/c/1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18

https://git.kernel.org/stable/c/18813b90032bfaafb225906a4d2b51be4dfc02c3

https://git.kernel.org/stable/c/15545ee71301e82d26d9a31b407ed0019eb62a60

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0019