« Volver al listado

CVE-2026-97432

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix P2P-Device binding handling

Our binding handling for P2P-Device can run into the following scenario, as observed by our testing:

Since the P2P device is removed from the binding and only re- added by unrelated code, but we want to keep the phy_ctxt around as a cache for future ROC usage, fix it by adding a boolean that indicates whether or not the P2P-Device should be added to the binding, and handle that in the binding iterator. That way, the station interface cannot re-add the P2P-Device to the binding when that isn't active.

Detalles técnicos trazas, registros y código del informe original
 - a station interface is connected on some channel
 - the P2P-Device does a remain-on-channel (ROC) on that channel
 - the ROC ends, and the P2P-Device is removed from the binding,
   but the phy_ctxt pointer is left around as a PHY cache so we
   don't need to recalibrate to the channel again and again in
   case it's not shared
 - a binding update by the station interface, even a removal,
   will re-add the P2P-Device to the binding
 - the P2P-Device is removed, which removes the PHY context, but
   it's still in the binding so the firmware crashes

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97432",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "84ef7cbe90e9e54c71c1da4e645ba34e1b33da77",
              "lessThan": "7be2fc679c8f657868988e41c0bb15bf5a454620",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "84ef7cbe90e9e54c71c1da4e645ba34e1b33da77",
              "lessThan": "b74e377cad9271950c57472867c469e4b5b2ff0c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ddf2212cfa5d9ef4fd289ce0d9dda728f2160b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "64c277f6329818db3124c9759cb9acf0f6070a54",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.5.12",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.2",
              "lessThan": "6.7",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/mvm/binding.c",
            "drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c",
            "drivers/net/wireless/intel/iwlwifi/mvm/mvm.h",
            "drivers/net/wireless/intel/iwlwifi/mvm/time-event.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/intel/iwlwifi/mvm/binding.c",
            "drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c",
            "drivers/net/wireless/intel/iwlwifi/mvm/mvm.h",
            "drivers/net/wireless/intel/iwlwifi/mvm/time-event.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:21.237",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/7be2fc679c8f657868988e41c0bb15bf5a454620",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b74e377cad9271950c57472867c469e4b5b2ff0c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix P2P-Device binding handling\n\nOur binding handling for P2P-Device can run into the following\nscenario, as observed by our testing:\n\n - a station interface is connected on some channel\n - the P2P-Device does a remain-on-channel (ROC) on that channel\n - the ROC ends, and the P2P-Device is removed from the binding,\n   but the phy_ctxt pointer is left around as a PHY cache so we\n   don't need to recalibrate to the channel again and again in\n   case it's not shared\n - a binding update by the station interface, even a removal,\n   will re-add the P2P-Device to the binding\n - the P2P-Device is removed, which removes the PHY context, but\n   it's still in the binding so the firmware crashes\n\nSince the P2P device is removed from the binding and only re-\nadded by unrelated code, but we want to keep the phy_ctxt around\nas a cache for future ROC usage, fix it by adding a boolean that\nindicates whether or not the P2P-Device should be added to the\nbinding, and handle that in the binding iterator. That way, the\nstation interface cannot re-add the P2P-Device to the binding\nwhen that isn't active."
    }
  ],
  "lastModified": "2026-09-25T13:17:26.827",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}