THREAT OPS › Threat News › [CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)
[CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)
<p>Posted by Abhinav Agarwal on Aug 02</p>An adjacent attacker can overflow iwd's stack with a spoofed 802.11k request<br /> once 17 BSS entries are cached. Hardened builds abort; a representative<br /> unhardened ARM32 layout permits saved-LR control. No network credentials<br /> are required on WPA2 without PMF.<br /> <br /> One maintainer reviewed and confirmed the findings and patches,
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://seclists.org/oss-sec/2026/q3/382