Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68407

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.

A flaw was found in the Linux kernel's Wi-Fi subsystem (nl80211). When processing beacon frames, the nl80211_parse_beacon() function may fail to properly free allocated RNR (Reduced Neighbor Report) data if there is a mismatch in the number of RNR and MBSSID (Multiple Basic Service Set Identifier) entries. This improper memory handling could lead to a memory leak, potentially allowing a remote attacker to cause a denial of service.

Отчет

This issue affects nl80211 beacon parsing with EMA MBSSID and RNR data. When RNR entries are fewer than MBSSID entries, the rejected RNR allocation is not freed before returning the error. Systems not using nl80211 beacon parsing are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred
Red Hat Enterprise Linux for NVIDIA 26kernelNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2513220kernel: wifi: nl80211: free RNR data on MBSSID mismatch

EPSS

Процентиль: 7%
0.00172
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.

nvd
21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.

CVSS3: 9.8
msrc
21 день назад

wifi: nl80211: free RNR data on MBSSID mismatch

debian
21 день назад

In the Linux kernel, the following vulnerability has been resolved: w ...

github
21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.

EPSS

Процентиль: 7%
0.00172
Низкий

5.5 Medium

CVSS3