CVE-2026-23315
Published: March 26, 2026Last modified: June 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoid a possible oob access. [fix check to also cover mgmt->u.action.u.addba_req.capab, correct Fixes tag]
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.1 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.167-r0) |
| 25 LTS | linux-lts | Fixed (6.12.80-r0) | |
| Stream | linux-lts | Fixed (6.18.35-r1) |
References
- https://git.kernel.org/stable/c/0fb3b94a9431a3800717e5c3b6fa2e1045a15029
- https://git.kernel.org/stable/c/4e10a730d1b511ff49723371ed6d694dd1b2c785
- https://git.kernel.org/stable/c/7ae7b093b7dba9548a3bc4766b9364b97db4732d
- https://git.kernel.org/stable/c/7b692dff8df0ba5feb8df00f27d906d6eb1fe627
- https://git.kernel.org/stable/c/84419556359bc96d3fe1623d47a64c86542566cc
- https://git.kernel.org/stable/c/9612d91f617231e03c49cb9b0c02f975a3b4f51f