wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
Summary
| CVE | CVE-2026-64174 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:59 UTC |
| Updated | 2026-07-19 16:17:59 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS
profile that has been split across multiple consecutive MBSSID elements.
Its while-loop calls
cfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)
but never advances mbssid_elem or sub_elem inside the body. Each
iteration therefore searches for a continuation that follows the same
fixed pair; the helper returns the same next_mbssid; and the same
next_sub bytes are memcpy()'d into merged_ie at a growing offset until
the buffer fills.
Advance both mbssid_elem and sub_elem to the just-consumed continuation
so the next call to cfg80211_get_profile_continuation() searches for a
further continuation beyond it (or returns NULL when none exists).
A specially-crafted malicious beacon can take advantage of this bug
to cause the kernel to spend an excessive amount of time in
cfg80211_merge_profile (up to as much as 2ms per beacon received),
which could theoretically be abused in some way. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 5817e1e5205498a5df66eba2b34e817f4210fd0f git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 cedbb608494ba1e7a5c6c56b7f1d3fd470094f28 git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8 git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 1ced0f5a851f9cae274545a42a06c459b7fd8881 git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 67915715fd3874057457363c87c63e18829527df git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 6cfae4914439878b8acb35c7e3b40096eeb2ad9c git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 1343a480f84b80c1249133a90ef87f8751d65cbb git |
Not specified |
| CNA |
Linux |
Linux |
affected fe806e4992c9047affd263bcc13b2c047029a726 7666dbb1bacc4ba522b96740cba7283d243d16e1 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.2 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.2 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.258 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.209 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.175 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/67915715fd3874057457363c87c63e18829527df |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1343a480f84b80c1249133a90ef87f8751d65cbb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7666dbb1bacc4ba522b96740cba7283d243d16e1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/cedbb608494ba1e7a5c6c56b7f1d3fd470094f28 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1ced0f5a851f9cae274545a42a06c459b7fd8881 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6cfae4914439878b8acb35c7e3b40096eeb2ad9c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5817e1e5205498a5df66eba2b34e817f4210fd0f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.