Impact
In the Linux kernel, a flaw in the cfg80211 subsystem was found where pending passive measurement requests (PMSR) are not properly aborted when a P2P or NAN interface is torn down. The kernel removes the subinterface from the driver before the measurement cleanup callback can run, freeing the request in cfg80211 while the lower driver still holds a reference to it. When the driver later reports a result, it may use this stale request, which can lead to kernel memory corruption, potential process crashes, or in the worst case, arbitrary code execution in kernel mode. This vulnerability is therefore a severe use‑after‑free type issue.
Affected Systems
The problem exists in any Linux kernel build that does not include the recent fix to call cfg80211_pmsr_wdev_down() before stopping P2P or NAN devices. No specific kernel release list is provided, so all versions are potentially affected until the patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. Its EPSS score is below 1%, meaning that, as of this analysis, exploitation probability is very low. The flaw is not listed in the CISA KEV catalog. Attack can be carried out from a local user with sufficient privileges to create or tear down P2P or NAN interfaces through nl80211, rfkill shutdown, or wireless device unregistration. The conditions required are a driver that still retains stale request state after interface removal, which is only the case when the specific missing cleanup path is exercised. While the likelihood is low, the impact is significant, so hardening or patching is recommended.
OpenCVE Enrichment