Junglewise Threat Intelligence

CVE-2026-64117: Linux Kernel mac80211 use-after-free in mesh fast-RX handling

CVE-2026-64117 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's wireless networking component could allow a nearby attacker to cause a system crash. The issue occurs when the system processes specific types of mesh network traffic, leading to a memory error. This primarily impacts the availability of devices using Linux-based Wi-Fi mesh networking.

Technical details

A slab-use-after-free vulnerability exists in net/mac80211/rx.c within the ieee80211_invoke_fast_rx() function. The root cause is a memory aliasing issue where the skb->cb storage is reused by ieee80211_rx_mesh_data() as IEEE80211_TX_INFO, while the caller still expects it to contain RX status information. In the unicast forward path, the mesh data handling may memset the info or free the skb entirely (no-route path), leading to a use-after-free when sta_stats_encode_rate(status) is subsequently called. An attacker within wireless range could potentially trigger this by sending specific mesh traffic. The issue has been patched by capturing the rate information before the mesh forwarding logic reuses or frees the buffer.

Affected products

  • Linux Linux Kernel 6.4 to 7.0.11

Timeline

  • 2026-05-09: other: Vulnerability fix authored
  • 2026-07-19: disclosed: CVE published

References

Related threats