CVE-2026-97432
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: fix P2P-Device binding handling
Our binding handling for P2P-Device can run into the following scenario, as observed by our testing:
Since the P2P device is removed from the binding and only re- added by unrelated code, but we want to keep the phy_ctxt around as a cache for future ROC usage, fix it by adding a boolean that indicates whether or not the P2P-Device should be added to the binding, and handle that in the binding iterator. That way, the station interface cannot re-add the P2P-Device to the binding when that isn't active.
Detalles técnicos trazas, registros y código del informe original
- a station interface is connected on some channel - the P2P-Device does a remain-on-channel (ROC) on that channel - the ROC ends, and the P2P-Device is removed from the binding, but the phy_ctxt pointer is left around as a PHY cache so we don't need to recalibrate to the channel again and again in case it's not shared - a binding update by the station interface, even a removal, will re-add the P2P-Device to the binding - the P2P-Device is removed, which removes the PHY context, but it's still in the binding so the firmware crashes
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97432",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "84ef7cbe90e9e54c71c1da4e645ba34e1b33da77",
"lessThan": "7be2fc679c8f657868988e41c0bb15bf5a454620",
"versionType": "git"
},
{
"status": "affected",
"version": "84ef7cbe90e9e54c71c1da4e645ba34e1b33da77",
"lessThan": "b74e377cad9271950c57472867c469e4b5b2ff0c",
"versionType": "git"
},
{
"status": "affected",
"version": "8ddf2212cfa5d9ef4fd289ce0d9dda728f2160b8",
"versionType": "git"
},
{
"status": "affected",
"version": "64c277f6329818db3124c9759cb9acf0f6070a54",
"versionType": "git"
},
{
"status": "affected",
"version": "6.5.12",
"lessThan": "6.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.2",
"lessThan": "6.7",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/wireless/intel/iwlwifi/mvm/binding.c",
"drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c",
"drivers/net/wireless/intel/iwlwifi/mvm/mvm.h",
"drivers/net/wireless/intel/iwlwifi/mvm/time-event.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/intel/iwlwifi/mvm/binding.c",
"drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c",
"drivers/net/wireless/intel/iwlwifi/mvm/mvm.h",
"drivers/net/wireless/intel/iwlwifi/mvm/time-event.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:21.237",
"references": [
{
"url": "https://git.kernel.org/stable/c/7be2fc679c8f657868988e41c0bb15bf5a454620",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b74e377cad9271950c57472867c469e4b5b2ff0c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix P2P-Device binding handling\n\nOur binding handling for P2P-Device can run into the following\nscenario, as observed by our testing:\n\n - a station interface is connected on some channel\n - the P2P-Device does a remain-on-channel (ROC) on that channel\n - the ROC ends, and the P2P-Device is removed from the binding,\n but the phy_ctxt pointer is left around as a PHY cache so we\n don't need to recalibrate to the channel again and again in\n case it's not shared\n - a binding update by the station interface, even a removal,\n will re-add the P2P-Device to the binding\n - the P2P-Device is removed, which removes the PHY context, but\n it's still in the binding so the firmware crashes\n\nSince the P2P device is removed from the binding and only re-\nadded by unrelated code, but we want to keep the phy_ctxt around\nas a cache for future ROC usage, fix it by adding a boolean that\nindicates whether or not the P2P-Device should be added to the\nbinding, and handle that in the binding iterator. That way, the\nstation interface cannot re-add the P2P-Device to the binding\nwhen that isn't active."
}
],
"lastModified": "2026-09-25T13:17:26.827",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}