SB2026072042 - Infinite loop in Linux kernel wireless
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Infinite loop (CVE-ID: CVE-2026-64174)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper loop state management in cfg80211_merge_profile() when processing a specially crafted malicious beacon containing split Multi-BSSID non-transmitted BSS profile elements. A remote attacker can send a specially crafted beacon to cause a denial of service.
The issue can cause the kernel to spend excessive time in the affected function for each beacon received.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1343a480f84b80c1249133a90ef87f8751d65cbb
- https://git.kernel.org/stable/c/1ced0f5a851f9cae274545a42a06c459b7fd8881
- https://git.kernel.org/stable/c/5817e1e5205498a5df66eba2b34e817f4210fd0f
- https://git.kernel.org/stable/c/67915715fd3874057457363c87c63e18829527df
- https://git.kernel.org/stable/c/6cfae4914439878b8acb35c7e3b40096eeb2ad9c
- https://git.kernel.org/stable/c/7666dbb1bacc4ba522b96740cba7283d243d16e1
- https://git.kernel.org/stable/c/c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8
- https://git.kernel.org/stable/c/cedbb608494ba1e7a5c6c56b7f1d3fd470094f28