CVE-2026-68405
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
ieee80211_do_stop() removes AP_VLAN packets from the parent AP ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then calls ieee80211_free_txskb() before dropping the lock.
ieee80211_free_txskb() is not just a passive SKB release. For SKBs with TX status state it can report a dropped frame through cfg80211/nl80211, and that path can reach netlink tap transmit. This is the same reason the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs under the queue lock and frees them after IRQ state is restored.
Leer descripción completaMostrar menos
The buggy scenario involves two paths, with each column showing the order within that path:
Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock, but move them to a local free queue. Drop the lock and restore IRQ state before calling ieee80211_free_txskb().
Detalles técnicos trazas, registros y código del informe original
AP_VLAN management TX: AP_VLAN stop:
1. attach ACK-status state 1. clear the running state
2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs
parent ps->bc_buf disabled
3. unlink the AP_VLAN SKB
4. call ieee80211_free_txskb()
WARNING: kernel/softirq.c:430 at __local_bh_enable_ipCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a
- https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461
- https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5
- https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d
- https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8
- https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789
- https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef
- https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-68405",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "659a81b62a61440b85e02c09903be861ae7679e5",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "aa01ef0ebbc3289154229ef58e65baf289eb9789",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "962f755a47d7ec3bbf6c709697d7f4c5f798441d",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "a424985c3ef2a87ce6057a853e18d0c441a86be8",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "4b8abf43bf34791c99d99dc3be13f897adefc461",
"versionType": "git"
},
{
"status": "affected",
"version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
"lessThan": "f3858d5b1432098c1936e03d6e03dd0e33facf60",
"versionType": "git"
}
],
"programFiles": [
"net/mac80211/iface.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/mac80211/iface.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:34.053",
"references": [
{
"url": "https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX: AP_VLAN stop:\n1. attach ACK-status state 1. clear the running state\n2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs\n parent ps->bc_buf disabled\n 3. unlink the AP_VLAN SKB\n 4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip"
}
],
"lastModified": "2026-08-19T17:20:48.317",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}