PT-2026-27644 · Linux+2 · Linux Kernel+2
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.13 through 6.17.0-5
Description
A flaw exists in the Linux kernel's mac80211 module related to handling of mesh networking frames. Specifically, a NULL pointer dereference can occur in the
mesh rx csa frame() function when processing SPECTRUM MGMT/CHL SWITCH action frames. This happens when a received CSA action frame lacks the Mesh Channel Switch Parameters IE, causing ieee802 11 parse elems() to set elems->mesh chansw params ie to NULL. Subsequently, the code attempts to dereference this NULL pointer at lines 1638 and 1642, leading to a kernel crash. A remote mesh peer with an established peer link (PLINK ESTAB) can trigger this by sending a crafted frame. The issue has been present since kernel version 3.13.Recommendations
Update the Linux kernel to a version beyond 6.17.0-5.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu