Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: stop PMSR before P2P and NAN teardown

PMSR request teardown must abort active measurements while the
wireless_dev is still present in the driver. cfg80211_leave_locked() and
cfg80211_stop_pd() already do this before invoking the driver's stop
callback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not.

Those helpers are also called directly by nl80211, rfkill shutdown, and
wireless_dev unregister paths. If one of these paths stops a P2P device
or NAN interface with a pending request, it removes the mac80211
subinterface from the driver first. Subsequent request cleanup cannot
reach the lower driver's abort callback, but cfg80211 frees the request
regardless. Driver state can then retain a stale request and use it when
it later reports a result.

Call cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN
interface. This keeps lower-driver request state and cfg80211 request
ownership in sync for all of the helpers' callers.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption from stale measurement request
Action: Patch Immediately
AI Analysis

Impact

In the Linux kernel, a flaw in the cfg80211 subsystem was found where pending passive measurement requests (PMSR) are not properly aborted when a P2P or NAN interface is torn down. The kernel removes the subinterface from the driver before the measurement cleanup callback can run, freeing the request in cfg80211 while the lower driver still holds a reference to it. When the driver later reports a result, it may use this stale request, which can lead to kernel memory corruption, potential process crashes, or in the worst case, arbitrary code execution in kernel mode. This vulnerability is therefore a severe use‑after‑free type issue.

Affected Systems

The problem exists in any Linux kernel build that does not include the recent fix to call cfg80211_pmsr_wdev_down() before stopping P2P or NAN devices. No specific kernel release list is provided, so all versions are potentially affected until the patch is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, indicating high severity. Its EPSS score is below 1%, meaning that, as of this analysis, exploitation probability is very low. The flaw is not listed in the CISA KEV catalog. Attack can be carried out from a local user with sufficient privileges to create or tear down P2P or NAN interfaces through nl80211, rfkill shutdown, or wireless device unregistration. The conditions required are a driver that still retains stale request state after interface removal, which is only the case when the specific missing cleanup path is exercised. While the likelihood is low, the impact is significant, so hardening or patching is recommended.

Generated by OpenCVE AI on September 19, 2026 at 15:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch which calls cfg80211_pmsr_wdev_down() before stopping P2P and NAN interfaces
  • If an immediate kernel upgrade is not possible, temporarily disable P2P or NAN functionality in the wireless driver until the fix is applied to prevent accidental teardown of interfaces while a measurement request is pending
  • Monitor kernel logs for evidence of stale request handling and, if possible, configure wireless to limit measurement operations to trusted processes only

Generated by OpenCVE AI on September 19, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardown PMSR request teardown must abort active measurements while the wireless_dev is still present in the driver. cfg80211_leave_locked() and cfg80211_stop_pd() already do this before invoking the driver's stop callback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not. Those helpers are also called directly by nl80211, rfkill shutdown, and wireless_dev unregister paths. If one of these paths stops a P2P device or NAN interface with a pending request, it removes the mac80211 subinterface from the driver first. Subsequent request cleanup cannot reach the lower driver's abort callback, but cfg80211 frees the request regardless. Driver state can then retain a stale request and use it when it later reports a result. Call cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN interface. This keeps lower-driver request state and cfg80211 request ownership in sync for all of the helpers' callers.
Title wifi: cfg80211: stop PMSR before P2P and NAN teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:45.339Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.977

Modified: 2026-09-18T18:17:54.750

Link: CVE-2026-90343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses