Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: nl80211: clean up color-change beacon data on errors

nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next
template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies.
A parsing failure returned directly instead of using the out: cleanup,
leaking any allocations completed before the error.

Allocate the nested attribute table before parsing beacon_next. Its
allocation failure can then return before beacon data exists, while a
later parsing failure uses out: to release the parsed data.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in the nl80211 Wi‑Fi subsystem of the Linux kernel, where nl80211_color_change() allocates beacon_next attributes through nl80211_parse_beacon(). A parsing failure returns immediately instead of executing the out: cleanup block, leaving previously allocated memory unreleased. This memory leak can, over time, consume kernel memory and cause a denial of service. The weakness corresponds to missing resource cleanup or release, as captured by CWE-404 and CWE-775.

Affected Systems

All Linux kernel installations that include the nl80211 Wi‑Fi driver are affected, regardless of distribution. The vulnerability is present in the kernel source itself, with no specific product version listed, so any pre‑patched kernel remains vulnerable.

Risk and Exploitability

The EPSS score is reported as <1 %, and the issue is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is most likely local, involving an application that sends malformed netlink messages to the nl80211 interface, or potentially remotely via a compromised wireless interface. The impact is resource exhaustion leading to kernel instability or a crash. Despite the low exploitation likelihood, the irreversible nature of kernel memory leaks warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 04:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest stable Linux kernel that includes the nl80211 cleanup fix.
  • If a kernel upgrade cannot be performed immediately, disable the wireless interface or configure the system to suppress color‑change beacon creation to avoid triggering the vulnerable code path.
  • Monitor kernel logs for nl80211 parsing errors and enforce strict memory limits or ulimits to mitigate the effect of any residual leaks.

Generated by OpenCVE AI on September 19, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
CWE-775

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: clean up color-change beacon data on errors nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies. A parsing failure returned directly instead of using the out: cleanup, leaking any allocations completed before the error. Allocate the nested attribute table before parsing beacon_next. Its allocation failure can then return before beacon data exists, while a later parsing failure uses out: to release the parsed data.
Title wifi: nl80211: clean up color-change beacon data on errors
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:55.591Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90346

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.343

Modified: 2026-09-17T17:17:33.343

Link: CVE-2026-90346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:30:17Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime