Double-Free Vulnerability in Linux Kernel Affects Wifi Functionality
CVE-2026-64570

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64570?

A memory management issue has been identified in the Linux kernel that affects the handling of fils_discovery in Wifi functionalities. The flaw lies in the ieee80211_set_fils_discovery() function, where a double-free condition can occur due to improper allocation management. Specifically, if kzalloc() fails after kfree_rcu() is called on an old template, the link can still point to an invalid memory address, leading to a potential double-free scenario. This can cause memory corruption and system instability, making it vital to apply the latest patches to mitigate this risk.

Affected Version(s)

Linux 3b1c256eb4aedfc71dd97d5951ccff824b41d628

Linux 3b1c256eb4aedfc71dd97d5951ccff824b41d628 < 5baaa1042f71dd4b8e418f2cdd516808702d229b

Linux 3b1c256eb4aedfc71dd97d5951ccff824b41d628 < 1981fba71797ec95e6755fb882cad88899a2a84f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.