{"api_version":"1","generated_at":"2026-09-24T23:02:46+00:00","cve":"CVE-2026-97492","urls":{"html":"https://cve.report/CVE-2026-97492","api":"https://cve.report/api/cve/CVE-2026-97492.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97492","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97492"},"summary":{"title":"wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed\n\nIn case reconfiguration of NAN fails, we call\nieee80211_handle_reconfig_failure, that marks all interfaces as not in\nthe driver.\nThen, at the error path of the reconfig, cfg80211_shutdown_all_interfaces\nis called to destroy all the interfaces.\n\nIf we have any other interface but the NAN one, for example a BSS\nstation, then when its state (links, stations) will be removed, we\nwon't tell the driver about this, because we will think that the\ninterfaces are not in the driver, and then drivers might remain with\ndangling pointers to objects like stations and links (at least for\niwlwifi this is the case).\n\nieee80211_handle_reconfig_failure is meant to be called after we cleaned\nup the state in the driver, there is no reason to call it for NAN\nreconfiguration failure.\n\nFix the code to just warn in such a case, as we do in other error paths\nin reconfig where it is too complicated to rewind.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:26","updated_at":"2026-09-24 17:17:26"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/6fb64029457cdcd77be546daf4c7c7cf04891857","name":"https://git.kernel.org/stable/c/6fb64029457cdcd77be546daf4c7c7cf04891857","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7a8a3ff2815501f78f494808355ddf37e08647d0","name":"https://git.kernel.org/stable/c/7a8a3ff2815501f78f494808355ddf37e08647d0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/60b96e44489d6775fe9cd8df619c29e0dc285c49","name":"https://git.kernel.org/stable/c/60b96e44489d6775fe9cd8df619c29e0dc285c49","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97492","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97492","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 60b96e44489d6775fe9cd8df619c29e0dc285c49 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 6fb64029457cdcd77be546daf4c7c7cf04891857 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 7a8a3ff2815501f78f494808355ddf37e08647d0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.111 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.53 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/mac80211/util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"60b96e44489d6775fe9cd8df619c29e0dc285c49","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6fb64029457cdcd77be546daf4c7c7cf04891857","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"7a8a3ff2815501f78f494808355ddf37e08647d0","status":"affected","version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","versionType":"git"},{"lessThan":"6.12.111","status":"affected","version":"0","versionType":"semver"},{"lessThan":"6.18.53","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/mac80211/util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed\n\nIn case reconfiguration of NAN fails, we call\nieee80211_handle_reconfig_failure, that marks all interfaces as not in\nthe driver.\nThen, at the error path of the reconfig, cfg80211_shutdown_all_interfaces\nis called to destroy all the interfaces.\n\nIf we have any other interface but the NAN one, for example a BSS\nstation, then when its state (links, stations) will be removed, we\nwon't tell the driver about this, because we will think that the\ninterfaces are not in the driver, and then drivers might remain with\ndangling pointers to objects like stations and links (at least for\niwlwifi this is the case).\n\nieee80211_handle_reconfig_failure is meant to be called after we cleaned\nup the state in the driver, there is no reason to call it for NAN\nreconfiguration failure.\n\nFix the code to just warn in such a case, as we do in other error paths\nin reconfig where it is too complicated to rewind."}],"providerMetadata":{"dateUpdated":"2026-09-24T16:04:40.294Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/60b96e44489d6775fe9cd8df619c29e0dc285c49"},{"url":"https://git.kernel.org/stable/c/6fb64029457cdcd77be546daf4c7c7cf04891857"},{"url":"https://git.kernel.org/stable/c/7a8a3ff2815501f78f494808355ddf37e08647d0"}],"title":"wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97492","datePublished":"2026-09-24T16:04:40.294Z","dateReserved":"2026-09-24T16:01:01.150Z","dateUpdated":"2026-09-24T16:04:40.294Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:26","lastModifiedDate":"2026-09-24 17:17:26","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97492","Ordinal":"1","Title":"wifi: mac80211: don't call ieee80211_handle_reconfig_failure whe","CVE":"CVE-2026-97492","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97492","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed\n\nIn case reconfiguration of NAN fails, we call\nieee80211_handle_reconfig_failure, that marks all interfaces as not in\nthe driver.\nThen, at the error path of the reconfig, cfg80211_shutdown_all_interfaces\nis called to destroy all the interfaces.\n\nIf we have any other interface but the NAN one, for example a BSS\nstation, then when its state (links, stations) will be removed, we\nwon't tell the driver about this, because we will think that the\ninterfaces are not in the driver, and then drivers might remain with\ndangling pointers to objects like stations and links (at least for\niwlwifi this is the case).\n\nieee80211_handle_reconfig_failure is meant to be called after we cleaned\nup the state in the driver, there is no reason to call it for NAN\nreconfiguration failure.\n\nFix the code to just warn in such a case, as we do in other error paths\nin reconfig where it is too complicated to rewind.","Type":"Description","Title":"wifi: mac80211: don't call ieee80211_handle_reconfig_failure whe"}]}}}