Executive brief
A vulnerability was identified in the Linux kernel's Wi-Fi management component (mac80211) that could lead to a system crash. The issue occurs when the system is processing radar detection signals, which are required for certain Wi-Fi frequencies to avoid interfering with weather or military radar. If exploited, this could cause the device to stop functioning or allow for unpredictable behavior during wireless operations.
Technical details
A slab-use-after-free vulnerability exists in the mac80211 subsystem of the Linux kernel within the 'ieee80211_dfs_radar_detected_work' function. The root cause is the use of unsafe list iteration ('list_for_each_entry') while calling 'ieee80211_dfs_cac_cancel', which can free and remove the current channel context ('chanctx') from the list. An attacker within wireless range could potentially trigger this condition during radar detection events (DFS). The fix replaces the iteration with 'list_for_each_entry_safe' to properly handle element removal during the loop. Patches have been applied to the mainline kernel and several stable branches.
Affected products
- Linux Linux Kernel Versions prior to 6.9 (fixed in 6.9 and various stable branches)
Timeline
- 2026-05-05: patched: Initial fix authored by Benjamin Berg
- 2026-05-28: disclosed: CVE published to NVD