wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
Published Sep 17, 2026
No CVSS score
EPSS 0.17%
Description
iwl_mvm_frob_txf_key_iter() tracks the last matched byte position in loop variable 'i'. When a full key match is found (match == keylen), 'i' points at the last byte of the matched key. The memset start offset should therefore be i + 1 - keylen, not i - keylen; the current code zeroes one byte before the match and leaves the final key byte un-sanitised.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.16
Unaffected
- ≥ 0, < 5.16
- ≥ 6.1.188, ≤ 6.1.*
- ≥ 6.12.110, ≤ 6.12.*
- ≥ 6.18.52, ≤ 6.18.*
- ≥ 6.6.157, ≤ 6.6.*
- ≥ 7.2.6, ≤ 7.2.*
- 7.3-rc1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82174 Advisory
- https://git.kernel.org/stable/c/1af000d75b1c96f7cbdf23f14d0ee1c51b12f8e6
- https://git.kernel.org/stable/c/2a77cb320e3998afa5e1ed0e95908b226aae9ed6
- https://git.kernel.org/stable/c/4c582ed61325135f841ca93667d7551a8e31e58d
- https://git.kernel.org/stable/c/5bcc933c6d47d795dab27458b9001c2d97130fd3
- https://git.kernel.org/stable/c/c9d8641aea01c3b2516483e128e1f557cfbcf44a
- https://git.kernel.org/stable/c/f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data