Executive brief
The Linux kernel's WiFi configuration interface (nl80211) contains a memory leak in its color-change beacon processing function. When beacon parsing fails, allocated memory structures (MBSSID and RNR data) are not properly cleaned up, resulting in memory leaks. This could lead to gradual memory exhaustion on systems processing WiFi color-change operations.
Technical details
The vulnerability is a resource leak (CWE-401) in the nl80211_color_change() function in net/wireless/nl80211.c. When nl80211_parse_beacon() is called to parse beacon_next template data, it allocates memory for params.beacon_next.mbssid_ies and .rnr_ies. If parsing fails after these allocations, the code previously returned directly without executing cleanup code, leaking the allocated memory. The fix reorders operations to allocate the nested attribute table before beacon parsing, ensuring that parsing failures reach the out: cleanup label that properly releases allocated beacon data. This affects beacon color-change operations in WiFi AP mode, which require authentication/privilege to trigger via netlink.
Affected products
- Linux Linux kernel multiple kernel versions (patch applies to 5.x, 6.x, and later series)
Timeline
- 2026-09-17: disclosed
- 2026-07-31: patched: Upstream fix committed; included in stable tree as of 2026-09-14