CVE-2026-68350EPSS p11.4%
CVE-2026-68350CVE-2026-68350
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: fix OOB read from off-by-two in TX status handler
The bounds check in carl9170_tx_process_status() uses
`i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing
2 extra iterations past valid _tx_status entries when the firmware-
controlled hdr.ext exceeds hdr.len/2. Fix by using the correct
comparison `i >= (cmd->hdr.len / 2)`.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.4% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-19 |