CVE-2026-97518 is a vulnerability in Linux Kernel
Published on September 24, 2026
wifi: cfg80211: reject duplicate wiphy cipher suite entries
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject duplicate wiphy cipher suite entries
Duplicate entries in wiphy->cipher_suites do not describe any
additional capability, but cfg80211 currently accepts them and leaves
individual consumers to deal with them.
One such consumer is the WEXT compatibility code, which appends a WEP
key length for each WEP cipher entry it sees. Repeated WEP entries can
therefore overflow the fixed iw_range::encoding_size array returned by
SIOCGIWRANGE.
Reject duplicate cipher suite entries in wiphy_register() instead.
This keeps the cipher suite invariant in one place and makes malformed
wiphy descriptions fail early with -EINVAL, rather than relying on a
single cfg80211 user to handle duplicates correctly.
Products Associated with CVE-2026-97518
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 1305f8b925fe92edf5fec183588dfc7db719180b is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 4cbb2360f4d8c29e67bc7a8bf6ba0ae096583923 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 7187d145d9042b037e4f10538f70cf95e380219f is affected.
- Before 6.12.111 is affected.
- Before 6.18.53 is affected.
- Version 6.12.111, <= 6.12.* is unaffected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2, <= * is unaffected.