Denial of Service Vulnerability in Linux Kernel Affecting Wi-Fi Functionality
CVE-2026-68411
What is CVE-2026-68411?
A vulnerability in the Linux kernel's Wi-Fi subsystem can lead to a denial of service condition due to improper handling of message lengths. The issue arises in the function hwsim_virtio_rx_work(), where lengths reported by a backend device may exceed buffer limits, resulting in a panic state. The vulnerability can be triggered by a malicious host, causing system disruptions. The fix implements checks to ensure that the reported lengths do not exceed the socket buffer's available space, thus safeguarding the integrity and stability of the kernel while preventing potential exploitation.
Affected Version(s)
Linux 5d44fe7c9808c56e136e59147bd932f5491520f1 < 82c5a30a66e2a7337d99476c67d6fc1a99c4250e
Linux 5d44fe7c9808c56e136e59147bd932f5491520f1
Linux 5d44fe7c9808c56e136e59147bd932f5491520f1 < 6dc76371a9a360c29de00df5b11563102d9d675a