Executive brief
A vulnerability in the Linux kernel's WiFi stack could allow a nearby malicious wireless access point to crash a connected device. By sending a specially crafted WiFi 7 management frame, an attacker can trigger a system failure (Blue Screen/Kernel Panic), leading to a complete service outage for the affected device. This issue primarily impacts newer WiFi 7 enabled systems using the mac80211 framework.
Technical details
An out-of-bounds array access vulnerability exists in the mac80211 WiFi stack within the ieee80211_ml_epcs function. The issue stems from a lack of bounds checking on the link_id extracted from a PRIO_ACCESS ML element's PER_STA_PROFILE subelement. While the link_id can be a value up to 15, the sdata->link array only contains 15 entries (indices 0-14). An attacker-controlled WiFi 7 Access Point can send an EPCS Enable Response action frame with link_id 15, causing the kernel to read past the array into adjacent memory. This results in a garbage pointer being passed to ieee80211_sta_wmm_params(), leading to a kernel NULL pointer dereference or general protection fault and a system crash. The vulnerability is reachable via unsolicited notifications if EPCS is enabled. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 6.15 to 7.1
Timeline
- 2026-05-15: other: Vulnerability reported and patch authored
- 2026-07-19: disclosed: CVE published and patches integrated into stable branches