CVE-2026-31780
published 2026-05-01CVE-2026-31780: In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation The variable valuesize…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
The variable valuesize is declared as u8 but accumulates the total
length of all SSIDs to scan. Each SSID contributes up to 33 bytes
(IEEE80211_MAX_SSID_LEN + 1), and with WILC_MAX_NUM_PROBED_SSID (10)
SSIDs the total can reach 330, which wraps around to 74 when stored
in a u8.
This causes kmalloc to allocate only 75 bytes while the subsequent
memcpy writes up to 331 bytes into the buffer, resulting in a 256-byte
heap buffer overflow.
Widen valuesize from u8 to u32 to accommodate the full range.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < 34a23fd9ddd683a03c7e8cc0ceded3e59e354b99 | 34a23fd9ddd683a03c7e8cc0ceded3e59e354b99 |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < 549f02d8ec94d39092ab6d9b103d0d6783a4b024 | 549f02d8ec94d39092ab6d9b103d0d6783a4b024 |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < bfbddeadd4779651403035ee177ae2f22f9f5521 | bfbddeadd4779651403035ee177ae2f22f9f5521 |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < 9907ac9b9a18b92fc34b9e4cb9e10f208dc1d3f7 | 9907ac9b9a18b92fc34b9e4cb9e10f208dc1d3f7 |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < c97b2a00059608592ad0d86fbb813a4f8cf9464b | c97b2a00059608592ad0d86fbb813a4f8cf9464b |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < d8388614de613c28eeb659c10115060a83739924 | d8388614de613c28eeb659c10115060a83739924 |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < 0c7f21d8bd2f93998b72b7a7f93152336aeca4dd | 0c7f21d8bd2f93998b72b7a7f93152336aeca4dd |
| linux | linux | >= c5c77ba18ea66aa05441c71e38473efb787705a4 < d049e56b1739101d1c4d81deedb269c52a8dbba0 | d049e56b1739101d1c4d81deedb269c52a8dbba0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.2 < 5.10.253 | 5.10.253 |
| linux | linux_kernel | >= 5.11 < 5.15.203 | 5.15.203 |
| linux | linux_kernel | >= 5.16 < 6.1.168 | 6.1.168 |
| linux | linux_kernel | >= 6.13 < 6.18.22 | 6.18.22 |
| linux | linux_kernel | >= 6.19 < 6.19.12 | 6.19.12 |
| linux | linux_kernel | >= 6.2 < 6.6.134 | 6.6.134 |
| linux | linux_kernel | >= 6.7 < 6.12.81 | 6.12.81 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hjw2-6262-hhr9: In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
The variabl
ghsa_unreviewed·2026-05-01
CVE-2026-31780 [HIGH] GHSA-hjw2-6262-hhr9: In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
The variabl
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
The variable valuesize is declared as u8 but accumulates the total
length of all SSIDs to scan. Each SSID contributes up to 33 bytes
(IEEE80211_MAX_SSID_LEN + 1), and with WILC_MAX_NUM_PROBED_SSID (10)
SSIDs the total can reach 330, which wraps around to 74 when stored
in a u8.
This causes kmalloc to allocate only 75 bytes while the subsequent
memcpy writes up to 331 bytes into the buffer, resulting in a 256-byte
heap buffer overflow.
Widen valuesize from u8 to u32 to accommodate the full range.
Red Hat
kernel: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
vendor_redhat·2026-05-01
CVE-2026-31780 CWE-190 kernel: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
kernel: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation
A flaw was found in the Linux kernel's wilc1000 Wi-Fi driver. An integer overflow vulnerability exists in the calculation of the SSID scan buffer size. This can lead to a heap buffer overflow when processing multiple Service Set Identifiers (SSIDs), potentially allowing a local attacker to cause a denial of service or execute arbitrary code.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Pack
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0c7f21d8bd2f93998b72b7a7f93152336aeca4ddhttps://git.kernel.org/stable/c/34a23fd9ddd683a03c7e8cc0ceded3e59e354b99https://git.kernel.org/stable/c/549f02d8ec94d39092ab6d9b103d0d6783a4b024https://git.kernel.org/stable/c/9907ac9b9a18b92fc34b9e4cb9e10f208dc1d3f7https://git.kernel.org/stable/c/bfbddeadd4779651403035ee177ae2f22f9f5521https://git.kernel.org/stable/c/c97b2a00059608592ad0d86fbb813a4f8cf9464bhttps://git.kernel.org/stable/c/d049e56b1739101d1c4d81deedb269c52a8dbba0https://git.kernel.org/stable/c/d8388614de613c28eeb659c10115060a83739924
2026-05-01
Published