-

CVE-2026-97492

wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed

In case reconfiguration of NAN fails, we call
ieee80211_handle_reconfig_failure, that marks all interfaces as not in
the driver.
Then, at the error path of the reconfig, cfg80211_shutdown_all_interfaces
is called to destroy all the interfaces.

If we have any other interface but the NAN one, for example a BSS
station, then when its state (links, stations) will be removed, we
won't tell the driver about this, because we will think that the
interfaces are not in the driver, and then drivers might remain with
dangling pointers to objects like stations and links (at least for
iwlwifi this is the case).

ieee80211_handle_reconfig_failure is meant to be called after we cleaned
up the state in the driver, there is no reason to call it for NAN
reconfiguration failure.

Fix the code to just warn in such a case, as we do in other error paths
in reconfig where it is too complicated to rewind.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < 026637b864b16dfae238e7e1accded820a3d7ae8
Status affected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < 6ef85dd9f8c62c9a465a32901d09475a114e67bd
Status affected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < f27a5bda84ff3b0fea3de7572ff48e518e66cf5d
Status affected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < 60b96e44489d6775fe9cd8df619c29e0dc285c49
Status affected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < 6fb64029457cdcd77be546daf4c7c7cf04891857
Status affected
Version 167e33f4f68cc8e4e3bdaf6d43641176c51f2d79
Version < 7a8a3ff2815501f78f494808355ddf37e08647d0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.9
Status affected
Version 0
Version < 4.9
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/60b96e44489d6775fe9cd8df619c29e0dc285c49
https://git.kernel.org/stable/c/6fb64029457cdcd77be546daf4c7c7cf04891857
https://git.kernel.org/stable/c/7a8a3ff2815501f78f494808355ddf37e08647d0
https://git.kernel.org/stable/c/026637b864b16dfae238e7e1accded820a3d7ae8
https://git.kernel.org/stable/c/6ef85dd9f8c62c9a465a32901d09475a114e67bd
https://git.kernel.org/stable/c/f27a5bda84ff3b0fea3de7572ff48e518e66cf5d