Junglewise Threat Intelligence

CVE-2026-53258: Linux Kernel memory leak in cfg80211 6 GHz scanning

CVE-2026-53258 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak was identified in the Linux kernel's wireless networking component when handling 6 GHz Wi-Fi scans. If a specific type of scan fails, the system may fail to release allocated memory, which over time could lead to reduced system performance or instability. This issue primarily affects devices using modern Wi-Fi hardware that supports 6 GHz bands.

Technical details

A memory leak exists in net/wireless/scan.c within the cfg80211_scan() function. When a split 6 GHz scan is triggered, the kernel allocates a cfg80211_scan_request_int object (rdev->int_scan_req). If the subsequent call to rdev_scan() fails, the allocated memory is not freed because the cleanup function ___cfg80211_scan_done() returns early when rdev->scan_req is NULL. An attacker or a malfunctioning user-space application (like wpa_supplicant) triggering repeated failed scans could cause kernel memory exhaustion. The fix introduces proper error checking and explicit kfree() calls when the scan fails.

Affected products

  • Linux Linux Kernel 5.10 to 6.18.36, 7.0.13

Timeline

  • 2026-06-01: other: Patch submitted by developer
  • 2026-06-25: advisory: CVE published by kernel.org and NVD

References

Related threats