7.8

CVE-2026-64568

wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure

ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points
at the object already queued for freeing. A later update or AP teardown
re-queues that same rcu_head; the second free is caught by KASAN when the
RCU sheaf is processed in softirq:

  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
  Free of addr ffff88800d06f300 by task exploit/145
   ...
   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
   rcu_free_sheaf (mm/slub.c:5850)
   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
   handle_softirqs (kernel/softirq.c:622)
  The buggy address belongs to the cache kmalloc-128 of size 128

Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 3b1c256eb4aedfc71dd97d5951ccff824b41d628
Version < ca27a81cd77b698e5eb586a011bee6800c7ee4bd
Status affected
Version 3b1c256eb4aedfc71dd97d5951ccff824b41d628
Version < d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae
Status affected
Version 3b1c256eb4aedfc71dd97d5951ccff824b41d628
Version < 0ace76e410d7f7d813b605825a3e593a79c3958f
Status affected
Version 3b1c256eb4aedfc71dd97d5951ccff824b41d628
Version < 1d067abcd37062426c59ec73dbc4e87a63f33fea
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd
https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae
https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f
https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea