SB20260812111 - Improper input validation in Linux kernel wireless
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68406)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in PMSR FTM request parsing in cfg80211/nl80211 when processing user-supplied PMSR FTM request attributes. A remote attacker can send a specially crafted request with an out-of-range preamble value to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/36230936468f0ba4930e94aef496fc229d4bb951
- https://git.kernel.org/stable/c/44ea65d779e2d23b2264fea6af2d0c666a3ec9fb
- https://git.kernel.org/stable/c/58320cb47df2accc7a20bb72c0150280732fa58f
- https://git.kernel.org/stable/c/922d71fbaf99c1d5318151a0cb0a42ad448d07d9
- https://git.kernel.org/stable/c/cfbda103aeae61071a122a6fc2bfe98cffbd7165