Data Handling Flaw in Linux Kernel Affecting WiFi Functionality
CVE-2026-68402
What is CVE-2026-68402?
A vulnerability exists in the Linux kernel's cfg80211 module, which fails to properly validate data length in certain WiFi elements. When processing non-inherited extension elements, the function cfg80211_is_element_inherited may attempt to read past valid memory boundaries if it encounters an empty data octet. This flaw can lead to out-of-bounds reads, creating a potential for exploitation through carefully crafted frames that trigger the vulnerability during frame parsing, specifically under contexts involving Multi-Link elements.
Affected Version(s)
Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 20c308d9a57722801961f816395bf825f7bde6bc
Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 84bd907361c56fbd5523eceb2682cb39da059bd5
Linux f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 < 11ac7a5e75f5132f1778e0c60981d30dc29fb869