Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: disconnect on CSA to channel 0

The refactor for the CSA parsing erroneously equates channel
zero and no information present, leading it to ignore a CSA
on an AP that advertises a switch to that (invalid) channel.
This leads to not disconnecting, which we should. For Intel
devices, this can lead to a firmware crash.

Fix this by using an int type for the channel number as well
as the opclass, and using a (negative) value that cannot be
encoded in the element to indicate it's not present.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via firmware crash from malformed CSA
Action: Kernel Update
AI Analysis

Impact

The Linux kernel’s mac80211 stack misinterprets a missing CSA channel value as zero, a value that is not a valid channel. When an access point advertises a switch to channel zero, the kernel fails to disconnect as it should, and on Intel wireless devices this misinterpretation can trigger a firmware crash. The vulnerability does not provide direct code‑execution or data‑exfiltration capabilities, but it can render the device non‑functional or force it to reboot, disrupting connectivity instead.

Affected Systems

All Linux kernel distributions that include the mac80211 wireless subsystem are potentially affected, with the most direct impact on Intel‑based Wi‑Fi hardware. No specific kernel release or version was enumerated in the advisory, so any kernel that has not incorporated the patch may be vulnerable.

Risk and Exploitability

The escalation is limited to a local or remote attacker that can control or spoof an access point. Because the issue requires a malformed CSA to be broadcast, normal user traffic does not trigger it. EPSS is reported as <1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, the severity of a firmware reboot can be high for critical infrastructure. The risk remains moderate, with exploitation feasible in environments where wireless traffic can be monitored or injected by an attacker.

Generated by OpenCVE AI on September 19, 2026 at 04:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that addresses the CSA parsing bug (see the referenced git commits).
  • If an immediate kernel upgrade is infeasible, consider disabling the CSA feature in the mac80211 configuration or updating driver settings to ignore channel zero announcements.
  • Monitor firmware stability and avoid connecting to Wi‑Fi networks that advertise a CSA to channel zero; vendors may provide a workaround log or device‑specific firmware update.

Generated by OpenCVE AI on September 19, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: disconnect on CSA to channel 0 The refactor for the CSA parsing erroneously equates channel zero and no information present, leading it to ignore a CSA on an AP that advertises a switch to that (invalid) channel. This leads to not disconnecting, which we should. For Intel devices, this can lead to a firmware crash. Fix this by using an int type for the channel number as well as the opclass, and using a (negative) value that cannot be encoded in the element to indicate it's not present.
Title wifi: mac80211: disconnect on CSA to channel 0
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:54.311Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90344

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.103

Modified: 2026-09-17T17:17:33.103

Link: CVE-2026-90344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:45:06Z

Weaknesses
  • CWE-20

    Improper Input Validation