8.8

CVE-2026-23246

wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration

link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Version < 650981e718e68005ca2760a6358134b8a98ebea4
Status affected
Version 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Version < bfde158d5d1322c0c2df398a8d1ccce04943be2e
Status affected
Version 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Version < f35ceec54d48e227fa46f8f97fd100a77b8eab15
Status affected
Version 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Version < d58d71c2167601762351962b9604808d3be94400
Status affected
Version 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Version < 162d331d833dc73a3e905a24c44dd33732af1fc5
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.130
Status unaffected
Version <= 6.12.*
Version 6.12.77
Status unaffected
Version <= 6.18.*
Version 6.18.17
Status unaffected
Version <= 6.19.*
Version 6.19.7
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.