Improper input validation in Linux kernel - CVE-2026-90344
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the mac80211 channel switch announcement parser when processing a channel switch announcement that advertises channel zero. A remote attacker can advertise a channel switch to channel zero to cause a denial of service.
The firmware-crash condition applies to Intel devices.