PT-2026-72184 · Linux · Linux Kernel

CVE-2026-68472

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the cfg80211 component where the cfg80211 gen new ie() function copies multi-link probe response elements from a parent frame without sufficient validation of the EHT multi-link element (MLE). The system only verified that the extension element exceeded one byte before calling ieee80211 mle get mld id(), which requires the caller to first use ieee80211 mle type ok() to ensure the MLE is valid and contains enough common information. A malicious access point can exploit this by sending a short EHT MLE in an MBSSID beacon, leading the ieee80211 mle get mld id() function to read past the Information Element (IE) boundary.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-68472

Affected Products

Linux Kernel