8.8
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
Basic Information
ID
CVE-2026-23246
Source
Linux
Published
Mar 18, 2026 at 10:05
Modified
Apr 2, 2026 at 14:43
Affected Product
Vendor
Linux
Product
Linux
Version
8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Affected Versions
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 6.5
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c
Linux Linux 6.5
References
- git.kernel.org /stable/c/650981e718e68005ca2760a6358134b8a98ebea4
- git.kernel.org /stable/c/bfde158d5d1322c0c2df398a8d1ccce04943be2e
- git.kernel.org /stable/c/f35ceec54d48e227fa46f8f97fd100a77b8eab15
- git.kernel.org /stable/c/d58d71c2167601762351962b9604808d3be94400
- git.kernel.org /stable/c/162d331d833dc73a3e905a24c44dd33732af1fc5