Junglewise Threat Intelligence

CVE-2026-74661: Linux kernel mac802154 netdev use-after-free in beacon worker

CVE-2026-74661 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IEEE 802.15.4 MAC layer (mac802154) beacon worker code contains a use-after-free vulnerability in network device lifecycle management. When a wireless interface is torn down while a beacon transmission worker thread is still running, the worker can continue to access freed memory, potentially causing system crashes or data corruption on devices using IEEE 802.15.4 wireless protocols (such as Zigbee or Thread devices).

Technical details

The vulnerability is a use-after-free in the mac802154_beacon_worker() function. The beacon worker reads a beacon request under RCU protection, derives a sub-interface pointer (sdata), then drops the RCU lock and continues using both sdata and its embedded wpan_dev structure. Meanwhile, mac802154_stop_beacons_locked() can cancel pending work, clear the beacon request, and free the associated memory. A beacon worker already running when interface teardown occurs will dereference the freed netdev private area after the RCU unlock. The fix applies lifetime-management discipline by taking a netdev reference (netdev_hold) while protected by RCU and releasing it (netdev_put) on all code paths that proceed after RCU unlock, preventing the netdev from being freed while the worker is still using it.

Affected products

  • Linux Linux kernel all versions with mac802154 beacon support

Timeline

  • 2026-08-22: disclosed
  • 2026-08-05: patched: upstream fix commit 5f26a690e8efa54315e4922368daf54e0b8f5515

References

Related threats