CVE-2026-64117
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb<br />
<br />
ieee80211_invoke_fast_rx() reads RX status through<br />
IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage<br />
that ieee80211_rx_mesh_data() reuses as IEEE80211_TX_INFO. In the<br />
unicast forward path, mesh_data does:<br />
<br />
info = IEEE80211_SKB_CB(fwd_skb);<br />
memset(info, 0, sizeof(*info));<br />
<br />
on the same skb the caller still names via rx->skb, then either<br />
queues the skb for TX (success) or kfree_skb()&#39;s it (no-route)<br />
before returning RX_QUEUED. The caller&#39;s RX_QUEUED arm then<br />
calls sta_stats_encode_rate(status) on memory that is either<br />
zeroed (success path) or freed (no-route path). The latter is<br />
KASAN slab-use-after-free in ieee80211_prepare_and_rx_handle.<br />
<br />
Fix by encoding the rate from status before invoking<br />
ieee80211_rx_mesh_data(), so the RX_QUEUED arm consumes a value<br />
captured while status was still backed by valid memory.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH



