Answer in brief
CVE-2026-68402 records a High severity (CVSS 7.1) vulnerability in wifi: cfg80211: bound element ID read when checking non-inheritance. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <20c308d9a57722801961f816395bf825f7bde6bc || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <84bd907361c56fbd5523eceb2682cb39da059bd5 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <11ac7a5e75f5132f1778e0c60981d30dc29fb869 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <ddf2773bcc8e49a43c561f22ec1e7924215d7947 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <cb8afea4655ff004fa7feee825d5c79783525383 | 20c308d9a57722801961f816395bf825f7bde6bc, 84bd907361c56fbd5523eceb2682cb39da059bd5, 11ac7a5e75f5132f1778e0c60981d30dc29fb869, ddf2773bcc8e49a43c561f22ec1e7924215d7947, cb8afea4655ff004fa7feee825d5c79783525383 |
| Linux/Linuxgeneric | 5.2 | Not reported |
| Linux/Linuxgeneric | >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <521dd5fe6d12b0d3c275f919738dc3a07117f4a5 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <24154c172246ae3f0e69bb17c9111095685ceedc || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <2d31ebb26a14f103c9cdc5287fb20cb2d4bde901 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <20c308d9a57722801961f816395bf825f7bde6bc || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <84bd907361c56fbd5523eceb2682cb39da059bd5 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <11ac7a5e75f5132f1778e0c60981d30dc29fb869 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <ddf2773bcc8e49a43c561f22ec1e7924215d7947 || >=f7dacfb11475ba777e1e84ccec2e14b0ba5a17a3 <cb8afea4655ff004fa7feee825d5c79783525383 | 521dd5fe6d12b0d3c275f919738dc3a07117f4a5, 24154c172246ae3f0e69bb17c9111095685ceedc, 2d31ebb26a14f103c9cdc5287fb20cb2d4bde901, 20c308d9a57722801961f816395bf825f7bde6bc, 84bd907361c56fbd5523eceb2682cb39da059bd5, 11ac7a5e75f5132f1778e0c60981d30dc29fb869, ddf2773bcc8e49a43c561f22ec1e7924215d7947, cb8afea4655ff004fa7feee825d5c79783525383 |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inheritance list. It does so after testing elem->id, but without verifying that the element actually has a data octet. A zero-length extension element (WLAN_EID_EXTENSION with length 0) therefore makes it read one octet past the end of the element. _ieee802_11_parse_elems_full() runs this check for every element of a frame once a non-inheritance context exists -- e.g. while parsing a per-STA profile of a Multi-Link element in a (re)association response, or a non-transmitted BSS profile -- so a crafted frame from an AP can trigger a one-octet slab-out-of-bounds read during element parsing: BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited Read of size 1 ... in net/wireless/scan.c Return early (treat the element as inherited) when an extension element carries no data, mirroring the existing handling of empty ID lists. The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.
Quoted source text, attributed separately from HOL analysis.