Answer in brief
CVE-2026-90343 records a Unknown severity vulnerability in wifi: cfg80211: stop PMSR before P2P and NAN teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <7a22cbc6c6bdd3c3811b4ce13875685c520f94de || >=9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <db3439ad11ac5e52decdefe784c98b21c3757848 || >=9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <6c5fc504d0d6934132637aa3db4b9b58148eaa78 | 7a22cbc6c6bdd3c3811b4ce13875685c520f94de, db3439ad11ac5e52decdefe784c98b21c3757848, 6c5fc504d0d6934132637aa3db4b9b58148eaa78 |
| Linux/Linuxgeneric | 5.0 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardown PMSR request teardown must abort active measurements while the wireless_dev is still present in the driver. cfg80211_leave_locked() and cfg80211_stop_pd() already do this before invoking the driver's stop callback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not. Those helpers are also called directly by nl80211, rfkill shutdown, and wireless_dev unregister paths. If one of these paths stops a P2P device or NAN interface with a pending request, it removes the mac80211 subinterface from the driver first. Subsequent request cleanup cannot reach the lower driver's abort callback, but cfg80211 frees the request regardless. Driver state can then retain a stale request and use it when it later reports a result. Call cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN interface. This keeps lower-driver request state and cfg80211 request ownership in sync for all of the helpers' callers.
Quoted source text, attributed separately from HOL analysis.