PT-2026-72183 · Linux · Linux Kernel
CVE-2026-68471
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the wifi ieee80211 component where the
ieee80211 mle size ok() function fails to properly validate the common information length for all known Multi-Link Element (MLE) types. Specifically, while ieee80211 mle common size() uses the first common-info octet as the length for all known MLE types, validation was only performed for Basic, Probe Request, and TDLS MLEs. Additionally, Reconfiguration MLEs skipped the length octet during minimum common size calculations, and Priority Access MLEs bypassed the validation of the advertised common information length.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel