CVE-2026-97511

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: avoid out-of-bounds access in monitor

In NAN, we don't know on what band the frame will be sent. Therefore we set info->band to NUM_NL80211_BANDS. However, this leads to out-of-bound access in ieee80211_add_tx_radiotap_header when we try to access the sbands array.

Fix it by not accessing the array if the band is NUM_NL80211_BANDS. This means that we will not report rate info for legacy rate in NAN. But nobody really cares about it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7f087f70e020b16a5b967332ee6e937817eaa173affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 03c41203ee5a833a9d7a7630be190830cede29d8affected
LinuxLinux0 < 6.18.53affected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References