0.0
NA
CVE-2026-74341
wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
Description

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.

INFO

Published Date :

Aug. 15, 2026, 6:22 a.m.

Last Modified :

Aug. 15, 2026, 6:22 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-74341 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Add a bounds check to prevent heap overflow from oversized firmware HAL responses.
  • Validate response length before copying to hal_buf.
  • Apply firmware updates with bounds checking.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-74341 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-74341 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-74341 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-74341 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': 'dae9cadf0925f1cbfb71306d60490890df3870a6', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': 'cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '15545ee71301e82d26d9a31b407ed0019eb62a60', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '18813b90032bfaafb225906a4d2b51be4dfc02c3', 'versionType': 'git'}, {'status': 'affected', 'version': '8e84c25821698bdef73c0329fb2022a4673b7adc', 'lessThan': '88a240d86d3d64521f9194abe185ac71cc74d0bd', 'versionType': 'git'}], 'programFiles': ['drivers/net/wireless/ath/wcn36xx/smd.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.13'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.13', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/net/wireless/ath/wcn36xx/smd.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.
    Added Reference https://git.kernel.org/stable/c/15545ee71301e82d26d9a31b407ed0019eb62a60
    Added Reference https://git.kernel.org/stable/c/18813b90032bfaafb225906a4d2b51be4dfc02c3
    Added Reference https://git.kernel.org/stable/c/1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18
    Added Reference https://git.kernel.org/stable/c/88a240d86d3d64521f9194abe185ac71cc74d0bd
    Added Reference https://git.kernel.org/stable/c/cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92
    Added Reference https://git.kernel.org/stable/c/dae9cadf0925f1cbfb71306d60490890df3870a6
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.