Executive brief
A vulnerability exists in the Linux kernel's Wi-Fi management component (cfg80211) that could allow an attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly handles memory for Wi-Fi networks with hidden names (SSIDs). An attacker within Wi-Fi range could exploit this to disrupt network operations or compromise the security of the affected device.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel wifi stack within the `cmp_bss()` and `cfg80211_update_known_bss()` functions in `net/wireless/scan.c`. The root cause is an improper memory management logic where beacon frame elements were being freed even when they were still being shared via the 'hidden_beacon_bss' pointer. This was introduced by a previous refactoring of BSS updates. An attacker within radio range (Adjacent) can trigger this condition by sending specific Wi-Fi management frames, leading to memory corruption. Patches have been released across multiple stable kernel branches to ensure beacon IEs are only freed if they are not shared.
Affected products
- Linux Linux Kernel Fixed in 26e8444, 5b7ae04, 6854476, 912c4b6, a8bb681, a97a979, b7d0892, ff04056
- Siemens RUGGEDCOM RST2428P < V3.3
- Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family < V3.3
Timeline
- 2025-08-13: patched: Initial patch authored
- 2025-09-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/26e84445f02ce6b2fe5f3e0e28ff7add77f35e08
- https://git.kernel.org/stable/c/5b7ae04969f822283a95c866967e42b4d75e0eef
- https://git.kernel.org/stable/c/6854476d9e1aeaaf05ebc98d610061c2075db07d
- https://git.kernel.org/stable/c/912c4b66bef713a20775cfbf3b5e9bd71525c716
- https://git.kernel.org/stable/c/a8bb681e879ca3c9f722aa08d3d7ae41c42a8807
- https://git.kernel.org/stable/c/a97a9791e455bb0cd5e7a38b5abcb05523d4e21c
- https://git.kernel.org/stable/c/b7d08929178c16398278613df07ad65cf63cce9d