Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Morse Micro
Morse Micro halowlink 2 |
|
| Vendors & Products |
Morse Micro
Morse Micro halowlink 2 |
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-119 CWE-200 |
Thu, 04 Jun 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah beacon or probe response frame containing a malformed Vendor Information Element. The function morse_vendor_find_vendor_ie() does not validate the IE length against the expected structure size before its result is passed to morse_vendor_rx_caps_ops_ie() and morse_vendor_fill_sta_vendor_info(), which read at fixed offsets into the IE data. Because the length check only requires the IE to be longer than 3 bytes, an attacker can supply an undersized IE, causing a heap out-of-bounds read of up to 9 bytes. No authentication, association, or user interaction is required. | |
| Title | Out-of-bounds read in morse.ko Vendor IE processing | |
| First Time appeared |
Morsemicro
Morsemicro halow Link 2 |
|
| CPEs | cpe:2.3:o:morsemicro:halow_link_2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Morsemicro
Morsemicro halow Link 2 |
|
| References |
|
Status: PUBLISHED
Assigner: Bugcrowd
Published:
Updated: 2026-06-04T13:01:15.389Z
Reserved: 2026-05-04T05:03:13.154Z
Link: CVE-2026-7764
Updated: 2026-06-04T13:01:02.890Z
Status : Awaiting Analysis
Published: 2026-06-04T02:16:17.700
Modified: 2026-06-04T15:16:58.787
Link: CVE-2026-7764
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:09:24Z