Junglewise Threat Intelligence

CVE-2026-90344: Linux kernel mac80211 channel switch handling denial of service

CVE-2026-90344 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's WiFi management component (mac80211) contains a logic error in how it processes channel switch announcements from access points. When an AP advertises an invalid channel 0 switch, the kernel fails to disconnect as it should, which can cause WiFi firmware crashes on Intel devices and leave systems in an unstable state.

Technical details

A refactored CSA (Channel Switch Announcement) parser in net/mac80211/spectmgmt.c incorrectly treats channel 0 and "no information present" as equivalent conditions. The vulnerable code used u8 type with zero as a sentinel value, making it impossible to distinguish between an actual channel-0 announcement (invalid but parseable) and a missing channel parameter. When an AP sends a CSA to channel 0, the kernel ignores it instead of disconnecting. This has been observed to cause firmware crashes on Intel WiFi devices. The fix changes the channel and operating-class fields to int type with -1 as the sentinel, allowing proper handling of malformed channel-0 announcements. The vulnerability affects the ieee80211_parse_ch_switch_ie function and requires no user interaction or authentication.

Affected products

  • Linux Linux kernel multiple versions (including 5.x, 6.x series)

Timeline

  • 2026-09-17: disclosed
  • 2026-08-02: patched: Fix merged upstream

References

Related threats