A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required. | |
| Title | Heap buffer overflow in morse.ko TIM IE processing | |
| First Time appeared |
Morsemicro
Morsemicro halow Link 2 |
|
| CPEs | cpe:2.3:o:morsemicro:halow_link_2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Morsemicro
Morsemicro halow Link 2 |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Bugcrowd
Published:
Updated: 2026-06-05T01:39:33.488Z
Reserved: 2026-05-04T05:03:00.671Z
Link: CVE-2026-7763
No data.
Status : Received
Published: 2026-06-05T02:17:14.640
Modified: 2026-06-05T02:17:14.640
Link: CVE-2026-7763
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.