« Volver al listado

CVE-2026-68405

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock

ieee80211_do_stop() removes AP_VLAN packets from the parent AP ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then calls ieee80211_free_txskb() before dropping the lock.

ieee80211_free_txskb() is not just a passive SKB release. For SKBs with TX status state it can report a dropped frame through cfg80211/nl80211, and that path can reach netlink tap transmit. This is the same reason the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs under the queue lock and frees them after IRQ state is restored.

Leer descripción completaMostrar menos

The buggy scenario involves two paths, with each column showing the order within that path:

Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock, but move them to a local free queue. Drop the lock and restore IRQ state before calling ieee80211_free_txskb().

Detalles técnicos trazas, registros y código del informe original
AP_VLAN management TX:             AP_VLAN stop:
1. attach ACK-status state         1. clear the running state
2. queue a multicast SKB on        2. take ps->bc_buf.lock with IRQs
   parent ps->bc_buf                  disabled
                                   3. unlink the AP_VLAN SKB
                                   4. call ieee80211_free_txskb()

WARNING: kernel/softirq.c:430 at __local_bh_enable_ip

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68405",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "659a81b62a61440b85e02c09903be861ae7679e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "aa01ef0ebbc3289154229ef58e65baf289eb9789",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "962f755a47d7ec3bbf6c709697d7f4c5f798441d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "a424985c3ef2a87ce6057a853e18d0c441a86be8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "4b8abf43bf34791c99d99dc3be13f897adefc461",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "397a7a24ef8c2967a3e8090013f9c54714110c48",
              "lessThan": "f3858d5b1432098c1936e03d6e03dd0e33facf60",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/mac80211/iface.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mac80211/iface.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:34.053",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX:             AP_VLAN stop:\n1. attach ACK-status state         1. clear the running state\n2. queue a multicast SKB on        2. take ps->bc_buf.lock with IRQs\n   parent ps->bc_buf                  disabled\n                                   3. unlink the AP_VLAN SKB\n                                   4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip"
    }
  ],
  "lastModified": "2026-08-19T17:20:48.317",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}