Malformed AMPDU Frame Handling Issue in Linux Kernel Affecting WiFi Connectivity
CVE-2026-64506

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64506?

A vulnerability in the Linux kernel affects WiFi connectivity by mishandling malformed AMPDU frames. During high traffic, particularly when a rekey process is underway, the initial AMPDU packet with certain sequence numbers may be dropped unexpectedly. This leads to potential disconnection from the Access Point (AP). The flaw stems from incorrect drop logic that fails to account for this specific scenario. A recent fix has been implemented, which includes initial state judgement to ensure that the status is reset only during a pairwise rekey operation.

Affected Version(s)

Linux bda294ed0ed05ada2a832b19a55dd4a6fa72b1a1 < 994994cfadaf1fd362dea9b8d9d633f85dc1b3c3

Linux bda294ed0ed05ada2a832b19a55dd4a6fa72b1a1 < 63ccdfac8677387dfdbd9d4336089e9823280704

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.