wifi: mac80211: fix NULL deref in mesh_matches_local()
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() unconditionally dereferences ie->mesh_config to compare mesh configuration parameters. When called from mesh_rx_csa_frame(), the parsed action-frame elements may not contain a Mesh Configuration IE, leaving ie->mesh_config NULL and triggering a kernel NULL pointer dereference. The other two callers are already safe: - ieee80211_mesh_rx_bcn_presp() checks !elems->mesh_config before calling mesh_matches_local() - mesh_plink_get_event() is only reached through mesh_process_plink_frame(), which checks !elems->mesh_config, too mesh_rx_csa_frame() is the only caller that passes raw parsed elements to mesh_matches_local() without guarding mesh_config. An adjacent attacker can exploit this by sending a crafted CSA action frame that includes a valid Mesh ID IE but omits the Mesh Configuration IE, crashing the kernel. The captured crash log: Oops: general protection fault, probably for non-canonical address ... KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] Workqueue: events_unbound cfg80211_wiphy_work [...] Call Trace: <TASK> ? __pfx_mesh_matches_local (net/mac80211/mesh.c:65) ieee80211_mesh_rx_queued_mgmt (net/mac80211/mesh.c:1686) [...] ieee80211_iface_work (net/mac80211/iface.c:1754 net/mac80211/iface.c:1802) [...] cfg80211_wiphy_work (net/wireless/core.c:426) process_one_work (net/kernel/workqueue.c:3280) ? assign_work (net/kernel/workqueue.c:1219) worker_thread (net/kernel/workqueue.c:3352) ? __pfx_worker_thread (net/kernel/workqueue.c:3385) kthread (net/kernel/kthread.c:436) [...] ret_from_fork_asm (net/arch/x86/entry/entry_64.S:255) </TASK> This patch adds a NULL check for ie->mesh_config at the top of mesh_matches_local() to return false early when the Mesh Configuration IE is absent.
- Yayın
- 26 Mar 2026
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,1 · 1. yüzdelik
- CWE
- CWE-476
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
22
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 22 / 40 · 5.5 / 10
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,1
Etkilenen sistemler
| Üretici | Ürün | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Etkilenen sürümler
NVD sürüm aralıkları (katalogdaki ürünler için). Stack’ine sürümle eklersen eşleşme bunlarla yapılır.
- linux linux kernel2.6.26.1 ve sonrası · 5.10.253 öncesi
- linux linux kernel5.11 ve sonrası · 5.15.203 öncesi
- linux linux kernel5.16 ve sonrası · 6.1.167 öncesi
- linux linux kernel6.2 ve sonrası · 6.6.130 öncesi
- linux linux kernel6.7 ve sonrası · 6.12.78 öncesi
- linux linux kernel6.13 ve sonrası · 6.18.20 öncesi
- linux linux kernel6.19 ve sonrası · 6.19.10 öncesi
- linux linux kernel2.6.26
- linux linux kernel7.0
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 2.6.26etkilenir
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · 14a4fd13657a3f2489db6566f081adfb27a49c64 öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · 74de6fa472b03bc8cde0a081484e9960bcbda568 öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · c1e3f2416fb27c816ce96d747d3e784e31f4d95c öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · 0a4da176ae4b4e075a19c00d3e269cfd5e05a813 öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · a90279e7f7ea0b7e923a1c5ebee9a6b78b6d1004 öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · 44699c6cdfce80a0f296b54ae9314461e3e41b3d öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · 7c55a3deaf7eaaafa2546f8de7fed19382a0a116 öncesietkilenir · git
- 2e3c8736820bf72a8ad10721c7e31d36d4fa7790 ve sonrası · c73bb9a2d33bf81f6eecaa0f474b6c6dbe9855bd öncesietkilenir · git
- 2.6.26 öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.170-1 öncesi | 6.1.170-1 |
| Debian:13 | linux | 6.12.85-1 öncesi | 6.12.85-1 |
| Debian:14 | linux | 6.19.10-1 öncesi | 6.19.10-1 |
| SUSE:Linux Enterprise Live Patching 12 SP5 | kernel-default | 4.12.14-122.317.1 öncesi | 4.12.14-122.317.1 |
| SUSE:Linux Enterprise Live Patching 12 SP5 | kgraft-patch-SLE12-SP5_Update_84 | 1-8.7.1 öncesi | 1-8.7.1 |
| SUSE:Linux Enterprise Server 12 SP5-LTSS | kernel-source | 4.12.14-122.317.1 öncesi | 4.12.14-122.317.1 |
| SUSE:Linux Enterprise Server 12 SP5-LTSS | kernel-syms | 4.12.14-122.317.1 öncesi | 4.12.14-122.317.1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Hemen
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Hemen
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Hemen
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77Bu hafta
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77Bu hafta
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77Bu hafta
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 0a4da176ae4b4e075a19c00d3e269cfd5e05a813 | Üretici (CNA) |
| Linux Linux | 14a4fd13657a3f2489db6566f081adfb27a49c64 | Üretici (CNA) |
| Linux Linux | 44699c6cdfce80a0f296b54ae9314461e3e41b3d | Üretici (CNA) |
| Linux Linux | 74de6fa472b03bc8cde0a081484e9960bcbda568 | Üretici (CNA) |
| Linux Linux | 7c55a3deaf7eaaafa2546f8de7fed19382a0a116 | Üretici (CNA) |
| Linux Linux | a90279e7f7ea0b7e923a1c5ebee9a6b78b6d1004 | Üretici (CNA) |
| Linux Linux | c1e3f2416fb27c816ce96d747d3e784e31f4d95c | Üretici (CNA) |
| Linux Linux | c73bb9a2d33bf81f6eecaa0f474b6c6dbe9855bd | Üretici (CNA) |
| Debian:linux | 6.1.170-1 · Debian:12 | Paket deposu (OSV) |
| SUSE:kernel-default | 4.12.14-122.317.1 · SUSE:Linux Enterprise Live Patching 12 SP5 | Paket deposu (OSV) |
| SUSE:kernel-source | 4.12.14-122.317.1 · SUSE:Linux Enterprise Server 12 SP5-LTSS | Paket deposu (OSV) |
| SUSE:kernel-syms | 4.12.14-122.317.1 · SUSE:Linux Enterprise Server 12 SP5-LTSS | Paket deposu (OSV) |
| SUSE:kgraft-patch-SLE12-SP5_Update_84 | 1-8.7.1 · SUSE:Linux Enterprise Live Patching 12 SP5 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Saldırı koşulları
- Sisteme yerel erişimi olan biri tetikleyebilir.
- Düşük yetkili bir hesap yeterli.
- Kullanıcının bir şey yapması gerekmez.
- Özel bir koşul gerekmez; tekrarlanabilir.
Başarılı olursa
- Gizlilik
- yok
- Bütünlük
- yok
- Erişilebilirlik
- yüksek · hizmet durdurulabilir
- Saldırı vektörü
- Yerel
- Karmaşıklık
- Düşük
- Gereken yetki
- Düşük
- Kullanıcı etkileşimi
- Gerekmez
- Kapsam
- Değişmez
- Gizlilik etkisi
- Yok
- Bütünlük etkisi
- Yok
- Erişilebilirlik etkisi
- Yüksek
Zayıflık sınıfı (CWE)
CWE-476 · NULL Pointer DereferenceCVSS vektörü
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd-primary
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
385 binden fazla zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinDeğişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/0a4da176ae4b4e075a19c00d3e269cfd5e05a813
- git.kernel.org/stable/c/14a4fd13657a3f2489db6566f081adfb27a49c64
- git.kernel.org/stable/c/44699c6cdfce80a0f296b54ae9314461e3e41b3d
- git.kernel.org/stable/c/74de6fa472b03bc8cde0a081484e9960bcbda568
- git.kernel.org/stable/c/7c55a3deaf7eaaafa2546f8de7fed19382a0a116
- git.kernel.org/stable/c/a90279e7f7ea0b7e923a1c5ebee9a6b78b6d1004
- git.kernel.org/stable/c/c1e3f2416fb27c816ce96d747d3e784e31f4d95c
- git.kernel.org/stable/c/c73bb9a2d33bf81f6eecaa0f474b6c6dbe9855bd
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.