-

CVE-2026-93805

wifi: cfg80211: validate rx/tx MLME callback frame lengths before access

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: validate rx/tx MLME callback frame lengths before access

cfg80211_rx_mlme_mgmt() and cfg80211_tx_mlme_mgmt() call tracepoints
before rejecting frames shorter than the frame-control field. After
that, they only require len >= 2 before dispatching into subtype
handlers that assume their fixed fields are present.

The frames that trip this are not shorter than 2 bytes; they are short
relative to their subtype. mwifiex is a concrete in-tree example on the
length side: mwifiex_process_mgmt_packet() only requires a 4-address
ieee80211_hdr plus the 2-byte firmware length prefix before handing the
frame to cfg80211_rx_mlme_mgmt(). After stripping the length prefix and
removing addr4, pkt_len can be exactly 24: a bare 3-address management
header with no reason-code body. The existing WARN_ON(len < 2) does not
fire on such a frame, and cfg80211_process_deauth() then reads
u.deauth.reason_code as a two-byte access starting at offset 24,
immediately past the 24-byte buffer.

Add a frame-control length gate, then validate each subtype's minimum
frame size in an if/else-if chain that mirrors the dispatch logic. Trace
only after the frame is known to be well-formed.

Side effects of this change:
 - The WARN_ON(len < 2) is dropped. It only guarded the frame_control
   read, never the subtype fixed fields, and it does not fire on the
   frames that actually trigger the out-of-bounds read (which are >= 2).
   The len >= 2 check is kept as the guard before dereferencing
   frame_control, but without the warning: these are exported callbacks
   and a malformed frame from a driver should be dropped silently rather
   than backtraced.
 - cfg80211_tx_mlme_mgmt() previously routed every non-deauth subtype
   through disassociation handling; it now silently ignores unrecognised
   subtypes.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < 6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a
Status affected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < ce2a3be6909462f49c34de96be71f0ad5f0d573f
Status affected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < 6bdf4dcff98df634e04ebf99f52027a48d7f78ff
Status affected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < 0ec738a0d361d7eb37188117166d201f9df622d3
Status affected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < 8f4127a93cf60d561ad39849a9ac763ba0e14db5
Status affected
Version 6829c878ecd24ff0ae41b4668c7e9d0f11b66942
Version < d5e4586546974179feca305a94e07fac3e9727fe
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.32
Status affected
Version 0
Version < 2.6.32
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0ec738a0d361d7eb37188117166d201f9df622d3
https://git.kernel.org/stable/c/8f4127a93cf60d561ad39849a9ac763ba0e14db5
https://git.kernel.org/stable/c/d5e4586546974179feca305a94e07fac3e9727fe
https://git.kernel.org/stable/c/6bdf4dcff98df634e04ebf99f52027a48d7f78ff
https://git.kernel.org/stable/c/6eb4bd50be53f5afbabb3a3b5153276e08fa7a4a
https://git.kernel.org/stable/c/ce2a3be6909462f49c34de96be71f0ad5f0d573f