Data Handling Flaw in Linux Kernel Affecting WiFi Functionality
CVE-2026-68402

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68402?

A vulnerability exists in the Linux kernel's cfg80211 module, which fails to properly validate data length in certain WiFi elements. When processing non-inherited extension elements, the function cfg80211_is_element_inherited may attempt to read past valid memory boundaries if it encounters an empty data octet. This flaw can lead to out-of-bounds reads, creating a potential for exploitation through carefully crafted frames that trigger the vulnerability during frame parsing, specifically under contexts involving Multi-Link elements.

Affected Version(s)

Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 20c308d9a57722801961f816395bf825f7bde6bc

Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 84bd907361c56fbd5523eceb2682cb39da059bd5

Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 11ac7a5e75f5132f1778e0c60981d30dc29fb869

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.