Linux Kernel Wifi Vulnerability in cfg80211 Merge Profile Function
CVE-2026-64174
What is CVE-2026-64174?
A vulnerability in the Linux kernel affects the cfg80211_merge_profile function, where improper handling of loop variables leads to performance degradation. Specifically, the while-loop within this function fails to advance the indices for Multi-BSSID elements, causing repeated processing of the same elements and excessive CPU usage, particularly when handling specially-crafted malicious beacons. Consequently, attackers may exploit this flaw to degrade system performance significantly, potentially impacting the overall stability and security of the affected device.
Affected Version(s)
Linux fe806e4992c9047affd263bcc13b2c047029a726 < 5817e1e5205498a5df66eba2b34e817f4210fd0f
Linux fe806e4992c9047affd263bcc13b2c047029a726
Linux fe806e4992c9047affd263bcc13b2c047029a726