« Volver al listado

CVE-2026-90346

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: nl80211: clean up color-change beacon data on errors

nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies. A parsing failure returned directly instead of using the out: cleanup, leaking any allocations completed before the error.

Allocate the nested attribute table before parsing beacon_next. Its allocation failure can then return before beacon data exists, while a later parsing failure uses out: to release the parsed data.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90346",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "dc1e3cb8da8b414b37208b2fb6755fef8122504b",
              "lessThan": "4e0a67fbe3d9e2e1d6f81dfc607184c6b0abd3dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dc1e3cb8da8b414b37208b2fb6755fef8122504b",
              "lessThan": "927ee844c47ac2aef22c8f7a35f098ff576b398b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/wireless/nl80211.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/wireless/nl80211.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:33.343",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4e0a67fbe3d9e2e1d6f81dfc607184c6b0abd3dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/927ee844c47ac2aef22c8f7a35f098ff576b398b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: clean up color-change beacon data on errors\n\nnl80211_color_change() calls nl80211_parse_beacon() for the beacon_next\ntemplate, which can allocate params.beacon_next.mbssid_ies and .rnr_ies.\nA parsing failure returned directly instead of using the out: cleanup,\nleaking any allocations completed before the error.\n\nAllocate the nested attribute table before parsing beacon_next. Its\nallocation failure can then return before beacon data exists, while a\nlater parsing failure uses out: to release the parsed data."
    }
  ],
  "lastModified": "2026-09-17T17:17:33.343",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}