Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64117

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: mac80211: capture fast-RX rate before mesh reuses skb-&gt;cb<br /> <br /> ieee80211_invoke_fast_rx() reads RX status through<br /> IEEE80211_SKB_RXCB(skb), which aliases the same skb-&gt;cb storage<br /> that ieee80211_rx_mesh_data() reuses as IEEE80211_TX_INFO. In the<br /> unicast forward path, mesh_data does:<br /> <br /> info = IEEE80211_SKB_CB(fwd_skb);<br /> memset(info, 0, sizeof(*info));<br /> <br /> on the same skb the caller still names via rx-&gt;skb, then either<br /> queues the skb for TX (success) or kfree_skb()&amp;#39;s it (no-route)<br /> before returning RX_QUEUED. The caller&amp;#39;s RX_QUEUED arm then<br /> calls sta_stats_encode_rate(status) on memory that is either<br /> zeroed (success path) or freed (no-route path). The latter is<br /> KASAN slab-use-after-free in ieee80211_prepare_and_rx_handle.<br /> <br /> Fix by encoding the rate from status before invoking<br /> ieee80211_rx_mesh_data(), so the RX_QUEUED arm consumes a value<br /> captured while status was still backed by valid memory.