PT-2026-46128 · Morse Micro · Halowlink 2
Published
2026-06-04
·
Updated
2026-06-04
·
CVE-2026-7764
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element. The function morse vendor find vendor ie() does not validate the IE length against the expected structure size before its result is passed to morse vendor rx caps ops ie() and morse vendor fill sta vendor info(), which read at fixed offsets into the IE data. Because the length check only requires the IE to be longer than 3 bytes, an attacker can supply an undersized IE, causing a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Halowlink 2