A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required. | |
| Title | Heap buffer overflow in morse.ko TIM IE processing | |
| First Time appeared |
Morsemicro
Morsemicro halow Link 2 |
|
| CPEs | cpe:2.3:o:morsemicro:halow_link_2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Morsemicro
Morsemicro halow Link 2 |
|
| References |
|
Status: PUBLISHED
Assigner: Bugcrowd
Published:
Updated: 2026-06-05T01:39:33.488Z
Reserved: 2026-05-04T05:03:00.671Z
Link: CVE-2026-7763
No data.
Status : Received
Published: 2026-06-05T02:17:14.640
Modified: 2026-06-05T02:17:14.640
Link: CVE-2026-7763
No data.
OpenCVE Enrichment
No data.