Heap-based buffer overflow in Linux kernel - CVE-2026-64446
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to a heap-based buffer overflow in rtw_cfg80211_set_wpa_ie() when handling a crafted WPA or WPA2 information element in a connect request via nl80211. A local user can send a specially crafted connect request to cause memory corruption.
The issue can overflow the 256-byte supplicant_ie buffer by one byte into the adjacent last_mic_err_time field.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64446
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/138cd190efd56ab36c9fdd8fef8749d06937f24b
- https://git.kernel.org/stable/c/2131621986c62c86109ce4d84cf73a73757eb8a6
- https://git.kernel.org/stable/c/46f66c16a95191d9aca07a72ae6b1252a244e26c
- https://git.kernel.org/stable/c/5a752a616e756844388a1a45404db9fc29fec655
- https://git.kernel.org/stable/c/5d7812360abf3143afcbf5efe4ef242448fa1f28
- https://git.kernel.org/stable/c/6f20d7b0ee47c470734a69379b0fc6647c519603
- https://git.kernel.org/stable/c/a94a643a80a84ceb8139061c3d6bf988d75e45a5
- https://git.kernel.org/stable/c/b9c4bf133c3c47e23baf4f5403b98a953bf58606