{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64515","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.793Z","datePublished":"2026-07-25T09:14:42.418Z","dateUpdated":"2026-08-05T12:42:32.369Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:42:32.369Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix MLE defragmentation\n\nIf either reconf or EPCS multi-link element (MLE) is contained in\na non-transmitted profile, the defragmentation routine is called\nwith a pointer to the defragmented copy, but the original elements.\n\nThis is incorrect for two reasons:\n - if the original defragmentation was needed, it will not find the\n   correct data\n - if the original frame is at a higher address, the parsing will\n   potentially overrun the heap data (though given the layout of\n   the buffers, only into the new defragmentation buffer, and then\n   it has to stop and fail once that's filled with copied data.\n\nFix it by tracking the container along with the pointer and in\ndoing so also unify the two almost identical defragmentation\nroutines."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":8.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - An attacker within radio range can inject spoofed WiFi beacons containing the crafted MBSSID profile and MLE. This is an adjacent-network attack.\nAC:L - The required EHT non-transmitted-BSS state is a vulnerable deployment condition, while the attacker controls the element layout and can repeatedly transmit trigger frames. No uncontrollable race must be won.\nPR:N - The receive path has no capability, namespace, login, or protocol-authentication requirement. Unauthenticated beacons are processed unless optional beacon protection is enabled.\nUI:N - An associated or associating station processes received beacons automatically. No contemporaneous victim action is required.\nS:U - The vulnerable parser and the affected kernel networking and link-management resources share the same security authority. There is no VM, sandbox, or IOMMU boundary crossing.\nC:H - The wrong container bound permits a nontrivial out-of-bounds read past the logical profile into heap scratch data. Although the current layout confines traversal within the allocation, the overread is not strictly limited to a few bytes, requiring C:H under the specified guidance.\nI:L - Destination bounds prevent an arbitrary-address heap write or credible control-flow primitive. Incorrectly reconstructed or truncated MLE data can nevertheless cause limited unauthorized changes to MLO link-removal or QoS state.\nA:H - Repeated unauthenticated beacon injection can keep MLE parsing and link reconfiguration failing or remove usable links. In a WiFi-dependent device this can cause complete, persistent network-service loss."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/parse.c"],"versions":[{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4","status":"affected","versionType":"git"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"55c479aae99b120489a432db9c717484e523dfd6","status":"affected","versionType":"git"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"722b3f86df80644463d29fe5451e30a617f74500","status":"affected","versionType":"git"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"a74e893f30db64cdce0fc7a96d3baa417bcd55f5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/parse.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4"},{"url":"https://git.kernel.org/stable/c/55c479aae99b120489a432db9c717484e523dfd6"},{"url":"https://git.kernel.org/stable/c/722b3f86df80644463d29fe5451e30a617f74500"},{"url":"https://git.kernel.org/stable/c/a74e893f30db64cdce0fc7a96d3baa417bcd55f5"}],"title":"wifi: mac80211: fix MLE defragmentation","x_generator":{"engine":"bippy-1.2.0"}}}}