{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/carl9170/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68350"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["carl9170"],"_cs_severities":["medium"],"_cs_tags":["informational","product-news"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eThe carl9170 wireless driver, commonly used in Linux-based kernel environments, contains a security flaw identified as CVE-2026-68350. The vulnerability originates from an off-by-two error within the TX status handler, which manages wireless frame transmission reporting. This logic error allows the driver to perform an out-of-bounds (OOB) memory read.\u003c/p\u003e\n\u003cp\u003eFor defenders and infrastructure security teams, this vulnerability represents a risk primarily in systems utilizing hardware supported by the carl9170 driver, such as specific USB wireless adapters. While the primary impact involves kernel-level memory disclosure or potential system crashes (Denial of Service), the exploitability depends on an attacker's ability to send or influence specially crafted 802.11 frames that trigger the flawed TX status logic. As of this report, no specific in-the-wild exploitation is documented.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to the exposure of sensitive kernel memory, potentially leaking cryptographic keys or other system information. Additionally, the out-of-bounds read may trigger a kernel panic, leading to a localized Denial of Service on the affected host. The impact is most significant in environments where the host is exposed to untrusted wireless traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the application of kernel security updates provided by the relevant Linux distribution vendors that maintain the carl9170 driver. Monitor system logs for kernel panics or driver-related errors originating from the carl9170 module, as these may indicate exploitation attempts causing system instability.\u003c/p\u003e\n","date_modified":"2026-08-11T09:58:18Z","date_published":"2026-08-11T09:58:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-carl9170-oob-read/","summary":"The carl9170 Wi-Fi driver contains an out-of-bounds read vulnerability due to an off-by-two error in the TX status handler, potentially leading to memory disclosure or system instability.","title":"Out-of-Bounds Read in carl9170 Wi-Fi Driver","url":"https://feed.craftedsignal.io/briefs/2026-08-carl9170-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Carl9170","version":"https://jsonfeed.org/version/1.1"}