Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4025 articles · 143446 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-31779PATCHED
intel · iwlwifi

wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matches may contain unwanted data. To guarantee safety, extend the validation in one of the checks to ensure sufficient packet length. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected Products

VendorProductVersions
inteliwlwifi5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 5ac54afd4d97ad8d94fe250c83b1924eb6d2268c, 6.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
linuxlinuxmitre_affected90%
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/f6abac936a0dfd31d6c3e49205ec0ee75a8f887f
  • https://git.kernel.org/stable/c/ffbed27ba15ef80d1c622eeedbfef03e501ae134
  • https://git.kernel.org/stable/c/e67d8c626ace80b0fa2b48c8ec0a46b508c93442
  • https://git.kernel.org/stable/c/dd90880eb5ec5442b37eb2b95688f4a63f4883e3
  • https://git.kernel.org/stable/c/ca0e9491b98ca4c5b44204b0b3dd8062a3b5fba2
  • https://git.kernel.org/stable/c/744fabc338e87b95c4d1ff7c95bc8c0f834c6d99

Related News (3 articles)

Tier B
BSI Advisories8d ago
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-31779 | Linux Kernel up to 6.19.11 wifi iwl_mvm_nd_match_info_handler out-of-bounds
→ No new info (linked only)
Tier C
Linux Kernel CVEs11d ago
CVE-2026-31779: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
f6abac936a0dfd31d6c3e49205ec0ee75a8f887fffbed27ba15ef80d1c622eeedbfef03e501ae134e67d8c626ace80b0fa2b48c8ec0a46b508c93442dd90880eb5ec5442b37eb2b95688f4a63f4883e3ca0e9491b98ca4c5b44204b0b3dd8062a3b5fba2744fabc338e87b95c4d1ff7c95bc8c0f834c6d9906.1.1686.6.1346.12.816.18.226.19.127.0
PublishedMay 1, 2026
Last enriched11d agov3
Trending Score15
Source articles3
Independent3
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2025-35969
CVE-2025-35969: Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3
Trending: 25
HIGHCVE-2026-43120
RDMA/irdma: Fix double free related to rereg_user_mr
Trending: 20
NONECVE-2025-35991
CVE-2025-35991: Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat
Trending: 20
PRE-CVE
Multiple Vulnerabilities in Intel Software Products
Trending: 20
NONECVE-2026-31691
igb: remove napi_synchronize() in igb_down()
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 1, 2026
Discovered by ZDM
May 1, 2026
Updated: affectedVersions
May 1, 2026
Updated: description, affectedVersions, severity
May 1, 2026
Patch Available
May 3, 2026

Version History

v3
Last enriched 11d ago
v3Tier C11d ago

Updated description with critical severity, new affected versions, and corrected exploit availability.

descriptionaffectedVersionsseverity
via VulDB
v2Tier C11d ago

Added CVE-2026-31779, updated affected versions, changed severity to HIGH, and provided a specific patch version.

affectedVersions
via Linux Kernel CVEs
v111d ago

Initial creation