Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Link | Tags |
---|---|
https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin | patch vendor advisory |