Executive brief
The Linux kernel's 802.11 wireless configuration module (cfg80211) has a synchronization bug in P2P device and NAN (Neighbor Awareness Network) interface shutdown. When these interfaces are torn down, pending peer measurement requests are not properly cleaned up in the wireless driver, leaving stale request state that can be misused when the driver later reports results. This can lead to unpredictable behavior or potential denial of service in wireless devices.
Technical details
The vulnerability is a use-after-free / state synchronization flaw in the cfg80211 wireless stack. When cfg80211_stop_p2p_device() or cfg80211_stop_nan() are called directly by nl80211, rfkill shutdown, or wireless device unregister paths, they remove the mac80211 subinterface from the driver before cleaning up pending PMSR (Peer Measurement Service Request) measurements. This causes the driver's abort callback to be unreachable, but cfg80211 still frees the request internally. The driver retains stale request state and can use it when reporting results, creating a mismatch between driver state and cfg80211 ownership. The fix adds calls to cfg80211_pmsr_wdev_down() before stopping P2P or NAN interfaces to ensure cleanup happens while the wireless device is still accessible to the driver.
Affected products
- Linux Linux kernel versions with cfg80211 PMSR support (roughly 5.0 and later)
Timeline
- 2026-09-17: disclosed
- 2026-08-02: patched: patch committed to linux.git/stable
- 2026-09-17: advisory