Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64174

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: cfg80211: advance loop vars in cfg80211_merge_profile()<br /> <br /> cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS<br /> profile that has been split across multiple consecutive MBSSID elements.<br /> Its while-loop calls<br /> <br /> cfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)<br /> <br /> but never advances mbssid_elem or sub_elem inside the body. Each<br /> iteration therefore searches for a continuation that follows the same<br /> fixed pair; the helper returns the same next_mbssid; and the same<br /> next_sub bytes are memcpy()&amp;#39;d into merged_ie at a growing offset until<br /> the buffer fills.<br /> <br /> Advance both mbssid_elem and sub_elem to the just-consumed continuation<br /> so the next call to cfg80211_get_profile_continuation() searches for a<br /> further continuation beyond it (or returns NULL when none exists).<br /> <br /> A specially-crafted malicious beacon can take advantage of this bug<br /> to cause the kernel to spend an excessive amount of time in<br /> cfg80211_merge_profile (up to as much as 2ms per beacon received),<br /> which could theoretically be abused in some way.

Impacto