PT-2026-72182 · Linux · Linux Kernel
CVE-2026-68470
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the mac80211 wireless driver where extension frames are not properly validated before being processed by the receive (RX) path. Because extension frames place the extension header at the regular 802.11 header offset, the generic RX path may allow helpers and interface dispatch code to read regular header address fields before unsupported extension subtypes are discarded. This affects the processing of S1G beacon extension frames, specifically within the
accept-frame, duplicate-detection, address-copy, and MLO address-translation paths. Additionally, the ieee80211 get bssid() function lacked length-safety when returning the S1G source-address pointer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel