« Volver al listado

CVE-2026-90344

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: disconnect on CSA to channel 0

The refactor for the CSA parsing erroneously equates channel zero and no information present, leading it to ignore a CSA on an AP that advertises a switch to that (invalid) channel. This leads to not disconnecting, which we should. For Intel devices, this can lead to a firmware crash.

Fix this by using an int type for the channel number as well as the opclass, and using a (negative) value that cannot be encoded in the element to indicate it's not present.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90344",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "21c3f8f95554feff9bed15703e89adbe582e0383",
              "lessThan": "099aadb2012d7490bc584cc5075ef11cbc33f2c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "21c3f8f95554feff9bed15703e89adbe582e0383",
              "lessThan": "e7bc5ab93acd1c3f54feeb9fa19ead3530168090",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "21c3f8f95554feff9bed15703e89adbe582e0383",
              "lessThan": "eef374088450bb91626e133c7172b8a0e969a522",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "21c3f8f95554feff9bed15703e89adbe582e0383",
              "lessThan": "cf57f0a674cc3e3cda1a789359cc1238b61b9d7d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/mac80211/spectmgmt.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mac80211/spectmgmt.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:33.103",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/099aadb2012d7490bc584cc5075ef11cbc33f2c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf57f0a674cc3e3cda1a789359cc1238b61b9d7d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e7bc5ab93acd1c3f54feeb9fa19ead3530168090",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eef374088450bb91626e133c7172b8a0e969a522",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: disconnect on CSA to channel 0\n\nThe refactor for the CSA parsing erroneously equates channel\nzero and no information present, leading it to ignore a CSA\non an AP that advertises a switch to that (invalid) channel.\nThis leads to not disconnecting, which we should. For Intel\ndevices, this can lead to a firmware crash.\n\nFix this by using an int type for the channel number as well\nas the opclass, and using a (negative) value that cannot be\nencoded in the element to indicate it's not present."
    }
  ],
  "lastModified": "2026-09-17T17:17:33.103",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}