A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information Element (IE element ID 0xD9). The function morse_dot11ah_find_s1g_caps_for_bssid() uses the IE length field directly as the size argument to memcpy without validating it against the 15-byte destination buffer. An attacker can supply up to 255 bytes, causing an overflow of up to 240 bytes of attacker-controlled data into adjacent kernel heap memory. The vulnerability is triggerable during normal scanning without authentication, association, or user interaction.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information Element (IE element ID 0xD9). The function morse_dot11ah_find_s1g_caps_for_bssid() uses the IE length field directly as the size argument to memcpy without validating it against the 15-byte destination buffer. An attacker can supply up to 255 bytes, causing an overflow of up to 240 bytes of attacker-controlled data into adjacent kernel heap memory. The vulnerability is triggerable during normal scanning without authentication, association, or user interaction. | |
| Title | Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing | |
| First Time appeared |
Morsemicro
Morsemicro halow Link 2 |
|
| CPEs | cpe:2.3:o:morsemicro:halow_link_2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Morsemicro
Morsemicro halow Link 2 |
|
| References |
|
Status: PUBLISHED
Assigner: Bugcrowd
Published:
Updated: 2026-06-05T01:36:20.993Z
Reserved: 2026-05-04T05:02:07.918Z
Link: CVE-2026-7762
No data.
Status : Received
Published: 2026-06-05T02:17:14.510
Modified: 2026-06-05T02:17:14.510
Link: CVE-2026-7762
No data.
OpenCVE Enrichment
No data.