CVE-2026-31780 Details
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation The variable valuesize is declared as u8 but accumulates the total length of all SSIDs to scan. Each SSID contributes up to 33 bytes (IEEE80211_MAX_SSID_LEN + 1), and with WILC_MAX_NUM_PROBED_SSID (10) SSIDs the total can reach 330, which wraps around to 74 when stored in a u8. This causes kmalloc to allocate only 75 bytes while the subsequent memcpy writes up to 331 bytes into the buffer, resulting in a 256-byte heap buffer overflow. Widen valuesize from u8 to u32 to accommodate the full range.
A heap buffer overflow vulnerability has been identified in the Linux kernel's WILC1000 wireless driver. The issue arises because the 'valuesize' variable, which is declared as an 8-bit unsigned integer, incorrectly accumulates the total length of SSIDs to be scanned. Each SSID can contribute up to 33 bytes, and with a maximum of 10 SSIDs, the total can reach 330 bytes. This exceeds the capacity of a u8, causing a wraparound that leads to improper memory allocation. The vulnerability allows for writing 256 bytes beyond the allocated buffer, creating a potential security risk.
The vulnerability has been addressed by changing the 'valuesize' variable from an 8-bit unsigned integer to a 32-bit unsigned integer, allowing it to correctly handle the maximum length of SSIDs. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0c7f21d8bd2f93998b72b7a7f93152336aeca4dd | kernel.org | Patch |
| https://git.kernel.org/stable/c/34a23fd9ddd683a03c7e8cc0ceded3e59e354b99 | kernel.org | Patch |
| https://git.kernel.org/stable/c/549f02d8ec94d39092ab6d9b103d0d6783a4b024 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9907ac9b9a18b92fc34b9e4cb9e10f208dc1d3f7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bfbddeadd4779651403035ee177ae2f22f9f5521 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c97b2a00059608592ad0d86fbb813a4f8cf9464b | kernel.org | Patch |
| https://git.kernel.org/stable/c/d049e56b1739101d1c4d81deedb269c52a8dbba0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d8388614de613c28eeb659c10115060a83739924 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.2, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.134 >= 6.7, < 6.12.81 >= 6.13, < 6.18.22 >= 6.19, < 6.19.12 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 3, 2026 | CVE Modified | kernel.org |
| May 1, 2026 | New CVE Received | kernel.org |