CVE-2026-74341
wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 15, 2026, 6:22 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products
The following products are affected by CVE-2026-74341
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
No affected product recoded yet
Solution
- Validate response length before copying to hal_buf.
- Apply firmware updates with bounds checking.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-74341.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-74341 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-74341
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-74341 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-74341 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': 'dae9cadf0925f1cbfb71306d60490890df3870a6', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': 'cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '15545ee71301e82d26d9a31b407ed0019eb62a60', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '18813b90032bfaafb225906a4d2b51be4dfc02c3', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '88a240d86d3d64521f9194abe185ac71cc74d0bd', 'versionType': 'git'}], 'programFiles': ['drivers/net/wireless/ath/wcn36xx/smd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.13'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.13', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/wireless/ath/wcn36xx/smd.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length. Added Reference https://git.kernel.org/stable/c/15545ee71301e82d26d9a31b407ed0019eb62a60 Added Reference https://git.kernel.org/stable/c/18813b90032bfaafb225906a4d2b51be4dfc02c3 Added Reference https://git.kernel.org/stable/c/1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18 Added Reference https://git.kernel.org/stable/c/88a240d86d3d64521f9194abe185ac71cc74d0bd Added Reference https://git.kernel.org/stable/c/cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92 Added Reference https://git.kernel.org/stable/c/dae9cadf0925f1cbfb71306d60490890df3870a6