CVE-2026-97500 is a vulnerability in Linux Kernel
Published on September 24, 2026
wifi: rtw89: phy: check length before parsing PHY status IE
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: phy: check length before parsing PHY status IE
Hardware might report PHY status IE with unexpected length, and parser
might access out of range. Check the length ahead.
Products Associated with CVE-2026-97500
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 213f9e0ab2b4f35fe8d342333238c6cc91513fbf is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 98e5720afd7495eece580238f232e3b3b4c022da is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 884495c39de1a02f42bd40051b921e2311d6ac91 is affected.
- Before 6.12.111 is affected.
- Before 6.18.53 is affected.
- Version 6.12.111, <= 6.12.* is unaffected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2, <= * is unaffected.