๐Ÿ” CVE Alert

CVE-2026-64568

UNKNOWN 0.0

wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old template before allocating the replacement. If the kzalloc() then fails, it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points at the object already queued for freeing. A later update or AP teardown re-queues that same rcu_head; the second free is caught by KASAN when the RCU sheaf is processed in softirq: BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850) Free of addr ffff88800d06f300 by task exploit/145 ... __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940) rcu_free_sheaf (mm/slub.c:5850) rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) The buggy address belongs to the cache kmalloc-128 of size 128 Queue the old object for kfree_rcu() only after the new one is published, matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3b1c256eb4aedfc71dd97d5951ccff824b41d628 < ca27a81cd77b698e5eb586a011bee6800c7ee4bd 3b1c256eb4aedfc71dd97d5951ccff824b41d628 < d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae 3b1c256eb4aedfc71dd97d5951ccff824b41d628 < 0ace76e410d7f7d813b605825a3e593a79c3958f 3b1c256eb4aedfc71dd97d5951ccff824b41d628 < 1d067abcd37062426c59ec73dbc4e87a63f33fea
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd git.kernel.org: https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae git.kernel.org: https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f git.kernel.org: https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea