-

CVE-2026-68405

wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock

ieee80211_do_stop() removes AP_VLAN packets from the parent AP
ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then
calls ieee80211_free_txskb() before dropping the lock.

ieee80211_free_txskb() is not just a passive SKB release. For SKBs with
TX status state it can report a dropped frame through cfg80211/nl80211,
and that path can reach netlink tap transmit. This is the same reason
the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs
under the queue lock and frees them after IRQ state is restored.

The buggy scenario involves two paths, with each column showing the
order within that path:

AP_VLAN management TX:             AP_VLAN stop:
1. attach ACK-status state         1. clear the running state
2. queue a multicast SKB on        2. take ps->bc_buf.lock with IRQs
   parent ps->bc_buf                  disabled
                                   3. unlink the AP_VLAN SKB
                                   4. call ieee80211_free_txskb()

Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,
but move them to a local free queue. Drop the lock and restore IRQ state
before calling ieee80211_free_txskb().

WARNING: kernel/softirq.c:430 at __local_bh_enable_ip
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < 0d2619e708e2ef02ba1c91642ea261d3f19d8f9a
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < 659a81b62a61440b85e02c09903be861ae7679e5
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < aa01ef0ebbc3289154229ef58e65baf289eb9789
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < 962f755a47d7ec3bbf6c709697d7f4c5f798441d
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < a424985c3ef2a87ce6057a853e18d0c441a86be8
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < 4b8abf43bf34791c99d99dc3be13f897adefc461
Status affected
Version 397a7a24ef8c2967a3e8090013f9c54714110c48
Version < f3858d5b1432098c1936e03d6e03dd0e33facf60
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.9
Status affected
Version 0
Version < 3.9
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.127
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef
https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d
https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8
https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461
https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60
https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a
https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5
https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789