Linux Kernel Wifi Vulnerability in cfg80211 Merge Profile Function
CVE-2026-64174

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64174?

A vulnerability in the Linux kernel affects the cfg80211_merge_profile function, where improper handling of loop variables leads to performance degradation. Specifically, the while-loop within this function fails to advance the indices for Multi-BSSID elements, causing repeated processing of the same elements and excessive CPU usage, particularly when handling specially-crafted malicious beacons. Consequently, attackers may exploit this flaw to degrade system performance significantly, potentially impacting the overall stability and security of the affected device.

Affected Version(s)

Linux fe806e4992c9047affd263bcc13b2c047029a726 < 5817e1e5205498a5df66eba2b34e817f4210fd0f

Linux fe806e4992c9047affd263bcc13b2c047029a726

Linux fe806e4992c9047affd263bcc13b2c047029a726

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.