wifi: mac80211: disconnect on CSA to channel 0
Summary
| CVE | CVE-2026-90344 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:33 UTC |
| Updated | 2026-09-17 17:17:33 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: disconnect on CSA to channel 0
The refactor for the CSA parsing erroneously equates channel
zero and no information present, leading it to ignore a CSA
on an AP that advertises a switch to that (invalid) channel.
This leads to not disconnecting, which we should. For Intel
devices, this can lead to a firmware crash.
Fix this by using an int type for the channel number as well
as the opclass, and using a (negative) value that cannot be
encoded in the element to indicate it's not present. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 21c3f8f95554feff9bed15703e89adbe582e0383 099aadb2012d7490bc584cc5075ef11cbc33f2c3 git |
Not specified |
| CNA |
Linux |
Linux |
affected 21c3f8f95554feff9bed15703e89adbe582e0383 e7bc5ab93acd1c3f54feeb9fa19ead3530168090 git |
Not specified |
| CNA |
Linux |
Linux |
affected 21c3f8f95554feff9bed15703e89adbe582e0383 eef374088450bb91626e133c7172b8a0e969a522 git |
Not specified |
| CNA |
Linux |
Linux |
affected 21c3f8f95554feff9bed15703e89adbe582e0383 cf57f0a674cc3e3cda1a789359cc1238b61b9d7d git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.9 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.9 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/099aadb2012d7490bc584cc5075ef11cbc33f2c3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/cf57f0a674cc3e3cda1a789359cc1238b61b9d7d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e7bc5ab93acd1c3f54feeb9fa19ead3530168090 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/eef374088450bb91626e133c7172b8a0e969a522 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.