Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23040

Опубликовано: 04 фев. 2026
Источник: redhat
CVSS3: 7.6

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.

Отчет

The mac80211_hwsim virtual WiFi driver contains an incorrect frequency constant used when generating NAN discovery window notifications on the 5 GHz band that can lead to Null pointer deref. In mac80211_hwsim_nan_dw_start the driver calls ieee80211_get_channel with 5475 MHz when nan_curr_dw_band is NL80211_BAND_5GHZ. That frequency does not correspond to a valid channel in typical wiphy channel tables so ieee80211_get_channel may return NULL. Subsequent NAN notification processing in cfg80211 may then dereference the channel pointer and crash the kernel in cfg80211_next_nan_dw_notif leading to a denial of service. The issue is most relevant in test and simulation environments where mac80211_hwsim is loaded and NAN simulation is enabled. A local attacker with permissions to configure wireless interfaces and NAN behavior can trigger the faulty path by enabling NAN simulation and causing 5 GHz NAN discovery window scheduling.

Меры по смягчению последствий

To mitigate this issue, prevent module mac80211_hwsim from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 10kernelFixedRHSA-2026:1813419.05.2026
Red Hat Enterprise Linux 9kernelFixedRHSA-2026:1858719.05.2026
Red Hat Enterprise Linux 9kernelFixedRHSA-2026:1858719.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2436806kernel: wifi: mac80211_hwsim: fix typo in frequency notification

7.6 High

CVSS3

Связанные уязвимости

ubuntu
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.

nvd
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.

debian
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: w ...

github
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.

oracle-oval
около 1 месяца назад

ELSA-2026-18587: kernel security update (MODERATE)

7.6 High

CVSS3