CVE-2026-64174
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
wifi: cfg80211: voorschot loop vars in cfg80211_merge_profile()
cfg80211_merge_profile() monteert een Multi-BSSID niet-verzonden BSS
profiel dat is verdeeld over meerdere opeenvolgende MBSSID-elementen. De while-loop-gesprekken
cfg80211_get_profile_continuation(dwz ielen, mbssid_elem, sub_elem)
maar gaat nooit vooruit mbssid_elem of sub_elem in het lichaam. Elke
iteratie zoekt daarom naar een vervolg dat hetzelfde volgt
vast paar; de helper retourneert hetzelfde next_mbssid; en hetzelfde
next_sub bytes zijn memcpy()'d in merged_ie met een groeiende offset tot
de buffer vult. Voer zowel mbssid_elem als sub_elem door naar de zojuist verbruikte voortzetting
dus de volgende oproep naar cfg80211_get_profile_continuation() zoekt naar een
verdere voortzetting daarbuiten (of geeft NULL terug als er geen bestaat). Een speciaal gemaakt kwaadaardig baken kan profiteren van deze bug
om ervoor te zorgen dat de kernel te veel tijd doorbrengt in
cfg80211_merge_profile (tot wel 2ms per ontvangen baken),
die theoretisch op de een of andere manier misbruikt zou kunnen worden.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS
profile that has been split across multiple consecutive MBSSID elements.
Its while-loop calls
cfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)
but never advances mbssid_elem or sub_elem inside the body. Each
iteration therefore searches for a continuation that follows the same
fixed pair; the helper returns the same next_mbssid; and the same
next_sub bytes are memcpy()'d into merged_ie at a growing offset until
the buffer fills.
Advance both mbssid_elem and sub_elem to the just-consumed continuation
so the next call to cfg80211_get_profile_continuation() searches for a
further continuation beyond it (or returns NULL when none exists).
A specially-crafted malicious beacon can take advantage of this bug
to cause the kernel to spend an excessive amount of time in
cfg80211_merge_profile (up to as much as 2ms per beacon received),
which could theoretically be abused in some way.