Linux Kernel Vulnerability in Mac80211 Affecting Multi-Link Element Handling
CVE-2026-64515

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64515?

A vulnerability in the Linux kernel's handling of multi-link elements (MLE) within the mac80211 subsystem has been identified. The issue arises when the defragmentation routine is invoked with a pointer referencing a defragmented copy while utilizing original, untransmitted profile elements. This results in potential discrepancies, as the original frame may contain data that is unreachable, leading to parsing errors or even potential heap overflows if the original frame is located at a higher memory address. A fix has been implemented to accurately track the container alongside the pointer, which also consolidates two previously similar defragmentation routines for improved efficiency and security.

Affected Version(s)

Linux 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff < 1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4

Linux 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff < 55c479aae99b120489a432db9c717484e523dfd6

Linux 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff < 722b3f86df80644463d29fe5451e30a617f74500

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.