CVE-2026-7764 Details
Description
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element. The function morse_vendor_find_vendor_ie() does not validate the IE length against the expected structure size before its result is passed to morse_vendor_rx_caps_ops_ie() and morse_vendor_fill_sta_vendor_info(), which read at fixed offsets into the IE data. Because the length check only requires the IE to be longer than 3 bytes, an attacker can supply an undersized IE, causing a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required.
A vulnerability allowing out-of-bounds read has been identified in the morse.ko HaLow Wi-Fi kernel driver, part of Morse Micro HaLowLink 2 software versions prior to 2.11.12. This vulnerability allows an unauthenticated attacker within radio range to either disclose a small amount of kernel heap memory or cause a denial-of-service condition, such as a kernel oops or panic. The issue arises when the driver processes a malformed Vendor Information Element in an 802.11ah beacon or probe response frame. The function morse_vendor_find_vendor_ie() fails to properly validate the length of the Information Element before passing it to other functions that read data at fixed offsets, leading to a heap out-of-bounds read of up to 9 bytes. Exploitation does not require authentication, association, or user interaction.
Users are advised to upgrade to Morse Micro HaLowLink 2 software version 2.11.12 or later. Customers using the morse.ko driver in their own Linux integrations should treat their integration as affected if it corresponds to a Morse Micro driver release prior to 2.11.12. Patched source can be obtained by contacting Morse Micro's security team.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.morsemicro.com/security-advisories/MM-SA-2026-003 | Bugcrowd Inc. | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| morsemicro halowlink 2 firmware | < 2.11.12 |
CPE
Remediation
| |
| morsemicro halowlink 2 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 30, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Bugcrowd Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | Bugcrowd Inc. |