Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64174

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
13/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: cfg80211: advance loop vars in cfg80211_merge_profile()<br /> <br /> cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS<br /> profile that has been split across multiple consecutive MBSSID elements.<br /> Its while-loop calls<br /> <br /> cfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)<br /> <br /> but never advances mbssid_elem or sub_elem inside the body. Each<br /> iteration therefore searches for a continuation that follows the same<br /> fixed pair; the helper returns the same next_mbssid; and the same<br /> next_sub bytes are memcpy()&amp;#39;d into merged_ie at a growing offset until<br /> the buffer fills.<br /> <br /> Advance both mbssid_elem and sub_elem to the just-consumed continuation<br /> so the next call to cfg80211_get_profile_continuation() searches for a<br /> further continuation beyond it (or returns NULL when none exists).<br /> <br /> A specially-crafted malicious beacon can take advantage of this bug<br /> to cause the kernel to spend an excessive amount of time in<br /> cfg80211_merge_profile (up to as much as 2ms per beacon received),<br /> which could theoretically be abused in some way.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.2 (incluyendo) 5.10.258 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.209 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.142 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.92 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.34 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.11 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*