Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211_hwsim: avoid NULL skb in stop queue drain

mac80211_hwsim_stop() drops any frames left in data->pending. The loop
currently checks skb_queue_empty() and then dequeues separately.

That split is racy with TX status handling, which can remove a pending
frame under the queue lock. If the last entry is removed after the empty
check, skb_dequeue() returns NULL and the stop path passes that NULL skb
to ieee80211_free_txskb().

Use skb_dequeue() as the loop condition instead. The dequeue result is the
object that stop owns and frees, and a concurrent status completion that
empties the queue simply makes the loop terminate.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the mac80211_hwsim module can drop a NULL skb object during a stop queue drain. A race between the queueing logic and transmit status handling permits a frame to be removed after an emptiness check but before the dequeue operation, causing ieee80211_free_txskb to receive a null pointer. The null deallocation results in a kernel crash, leading to a denial of service for the affected system.

Affected Systems

All Linux kernel builds that include the mac80211_hwsim wireless simulator, which is present in the mainline kernel, are potentially affected. No specific version range is listed, so the vulnerability applies to all releases until the patch is applied.

Risk and Exploitability

The vulnerability can crash the kernel, causing a denial of service. The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog, meaning no publicly documented exploitation yet. Based on the description, the attack would likely be limited to a local race condition within the mac80211_hwsim module; an attacker would need to trigger transmission events that interact with the driver to force the race, so reaching the vulnerable state requires relatively rudimentary interaction.

Generated by OpenCVE AI on September 19, 2026 at 08:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that replaces the skb_queue_empty()/skb_dequeue split with a single skb_dequeue loop so no NULL skb is passed to the free routine
  • Upgrade to the latest stable Linux kernel release that contains the mac80211_hwsim patch; if an update is not possible, rebuild your kernel with the applicable commit applied
  • If the mac80211_hwsim module is not required for your deployment, disable or remove the module to eliminate the attack vector

Generated by OpenCVE AI on September 19, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: avoid NULL skb in stop queue drain mac80211_hwsim_stop() drops any frames left in data->pending. The loop currently checks skb_queue_empty() and then dequeues separately. That split is racy with TX status handling, which can remove a pending frame under the queue lock. If the last entry is removed after the empty check, skb_dequeue() returns NULL and the stop path passes that NULL skb to ieee80211_free_txskb(). Use skb_dequeue() as the loop condition instead. The dequeue result is the object that stop owns and frees, and a concurrent status completion that empties the queue simply makes the loop terminate.
Title wifi: mac80211_hwsim: avoid NULL skb in stop queue drain
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:46.136Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.083

Modified: 2026-09-17T17:18:10.083

Link: CVE-2026-93149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:13Z

Weaknesses