CVE-2026-90344

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: disconnect on CSA to channel 0

The refactor for the CSA parsing erroneously equates channel zero and no information present, leading it to ignore a CSA on an AP that advertises a switch to that (invalid) channel. This leads to not disconnecting, which we should. For Intel devices, this can lead to a firmware crash.

Fix this by using an int type for the channel number as well as the opclass, and using a (negative) value that cannot be encoded in the element to indicate it's not present.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux21c3f8f95554feff9bed15703e89adbe582e0383 < 099aadb2012d7490bc584cc5075ef11cbc33f2c3affected
LinuxLinux21c3f8f95554feff9bed15703e89adbe582e0383 < e7bc5ab93acd1c3f54feeb9fa19ead3530168090affected
LinuxLinux21c3f8f95554feff9bed15703e89adbe582e0383 < eef374088450bb91626e133c7172b8a0e969a522affected
LinuxLinux21c3f8f95554feff9bed15703e89adbe582e0383 < cf57f0a674cc3e3cda1a789359cc1238b61b9d7daffected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References