« Volver al listado

CVE-2026-90345

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: fix P2P action frame handling without device vif

Some P2P action frame paths assume the P2P device vif is always available. That is not true when userspace sends non-P2P public action frames through the primary interface, or when action-frame abort runs after the P2P device vif has not been created.

Fall back to the primary vif when aborting an action frame without a P2P device vif, and guard P2P device saved IE access before using it for peer channel search.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90345",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6eda4e2c54255cd26a58d2fcec73ec3bff7a515b",
              "lessThan": "f26e1b16904555e171292e183c3cfc1c38159fc5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6eda4e2c54255cd26a58d2fcec73ec3bff7a515b",
              "lessThan": "1b1edb9ebed49099bdc924cef49a9aea8b552199",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:33.230",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1b1edb9ebed49099bdc924cef49a9aea8b552199",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f26e1b16904555e171292e183c3cfc1c38159fc5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix P2P action frame handling without device vif\n\nSome P2P action frame paths assume the P2P device vif is always\navailable. That is not true when userspace sends non-P2P public action\nframes through the primary interface, or when action-frame abort runs\nafter the P2P device vif has not been created.\n\nFall back to the primary vif when aborting an action frame without a P2P\ndevice vif, and guard P2P device saved IE access before using it for\npeer channel search."
    }
  ],
  "lastModified": "2026-09-17T17:17:33.230",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}