CVE-2026-64515

Source
https://cve.org/CVERecord?id=CVE-2026-64515
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64515.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64515
Downstream
Published
2026-07-25T09:14:42.418Z
Modified
2026-07-28T03:46:52.938003272Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H CVSS Calculator
Summary
wifi: mac80211: fix MLE defragmentation
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix MLE defragmentation

If either reconf or EPCS multi-link element (MLE) is contained in a non-transmitted profile, the defragmentation routine is called with a pointer to the defragmented copy, but the original elements.

This is incorrect for two reasons: - if the original defragmentation was needed, it will not find the correct data - if the original frame is at a higher address, the parsing will potentially overrun the heap data (though given the layout of the buffers, only into the new defragmentation buffer, and then it has to stop and fail once that's filled with copied data.

Fix it by tracking the container along with the pointer and in doing so also unify the two almost identical defragmentation routines.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64515.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff
Fixed
1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4
Fixed
55c479aae99b120489a432db9c717484e523dfd6
Fixed
722b3f86df80644463d29fe5451e30a617f74500
Fixed
a74e893f30db64cdce0fc7a96d3baa417bcd55f5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64515.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64515.json"