CVE-2026-68407

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: nl80211: free RNR data on MBSSID mismatch

nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries.

The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxdbbb27e183b1568d5a907ace1cd144b0709ea52a < fa9592ef7de11f8c7042315d9bc20e91a97f679eaffected
LinuxLinuxdbbb27e183b1568d5a907ace1cd144b0709ea52a < 312c8b9d7836ef58e552619a8c19be08b04032bbaffected
LinuxLinuxdbbb27e183b1568d5a907ace1cd144b0709ea52a < fb052a6e2fa866384d8edc237746583ec94c15afaffected
LinuxLinuxdbbb27e183b1568d5a907ace1cd144b0709ea52a < 6f919f29e9b75793104709987131b8d910d7800aaffected
LinuxLinuxdbbb27e183b1568d5a907ace1cd144b0709ea52a < 07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29caffected
LinuxLinux56189d7bc30531def6b999f27940ee43c6ff2569affected
LinuxLinux6.1.160 < 6.2affected
LinuxLinux6.4affected
LinuxLinux0 < 6.4unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc4 <= *unaffected

Weaknesses

References