CVE-2026-53182 (GCVE-0-2026-53182)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores the parsed element count in a u8-backed cfg80211_rnr_elems::cnt field and uses that count to size the flexible array allocation. Reject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches 255, before incrementing it again. This keeps the parser aligned with the data structure it fills and matches the existing bound check used by nl80211_parse_mbssid_elems().
Impacted products
Vendor Product Version
Linux Linux Version: 56189d7bc30531def6b999f27940ee43c6ff2569
Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a
Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a
Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a
Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a
Version: dbbb27e183b1568d5a907ace1cd144b0709ea52a
Version: 6.1.160   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/wireless/nl80211.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "fc0ec2fc02dfe52c5821f36fbccf6a45df43f508",
              "status": "affected",
              "version": "56189d7bc30531def6b999f27940ee43c6ff2569",
              "versionType": "git"
            },
            {
              "lessThan": "688fcac7054abc680c0eef753f2bb772cfaf8cf7",
              "status": "affected",
              "version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
              "versionType": "git"
            },
            {
              "lessThan": "30c3fa80f423613efdda3deca4af52ff7d20e4e2",
              "status": "affected",
              "version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
              "versionType": "git"
            },
            {
              "lessThan": "265c07c09c837621730d35f02975207a1224bf05",
              "status": "affected",
              "version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
              "versionType": "git"
            },
            {
              "lessThan": "ecbf3c45add30a0857414e156bdb9c79906f0ff6",
              "status": "affected",
              "version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
              "versionType": "git"
            },
            {
              "lessThan": "4cd92957e8f8cc4ebfe8a5d4203c14c592fde6b1",
              "status": "affected",
              "version": "dbbb27e183b1568d5a907ace1cd144b0709ea52a",
              "versionType": "git"
            },
            {
              "lessThan": "6.1.176",
              "status": "affected",
              "version": "6.1.160",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/wireless/nl80211.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "lessThan": "6.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.94",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.36",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "6.1.160",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.94",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.36",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.13",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: reject oversized EMA RNR lists\n\nnl80211_parse_rnr_elems() stores the parsed element count in a\nu8-backed cfg80211_rnr_elems::cnt field and uses that count to size\nthe flexible array allocation.\n\nReject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches\n255, before incrementing it again. This keeps the parser aligned with\nthe data structure it fills and matches the existing bound check used\nby nl80211_parse_mbssid_elems()."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable parser is reached through local nl80211 generic-netlink commands that configure AP beacon data, not by received WiFi frames or remote network traffic.\nAC:L - An attacker who can send the command can deterministically provide 256 or more nested EMA RNR elements; there is no race or condition outside the attacker\u0027s control beyond targeting an affected AP-capable configuration.\nPR:L - The commands require CAP_NET_ADMIN via GENL_UNS_ADMIN_PERM, which is checked in the relevant network namespace; under kernel scoring guidance this is low privilege because CAP_NET_ADMIN may be available through user namespaces.\nUI:N - No victim action is required after the attacker sends the crafted nl80211 request.\nS:U - The corruption occurs inside the kernel and impacts the same kernel security authority; it is not a VM escape or other cross-scope boundary violation.\nC:H - The u8 count wrap causes an undersized flexible-array allocation followed by attacker-influenced out-of-bounds heap writes, which is memory corruption plausibly usable for kernel memory disclosure.\nI:H - The bug is a kernel heap out-of-bounds write of RNR element metadata past the allocation, making arbitrary corruption or control-flow compromise defensible.\nA:H - The same heap corruption can readily crash or panic the kernel even if not weaponized for code execution."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:33:48.954Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/fc0ec2fc02dfe52c5821f36fbccf6a45df43f508"
        },
        {
          "url": "https://git.kernel.org/stable/c/688fcac7054abc680c0eef753f2bb772cfaf8cf7"
        },
        {
          "url": "https://git.kernel.org/stable/c/30c3fa80f423613efdda3deca4af52ff7d20e4e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/265c07c09c837621730d35f02975207a1224bf05"
        },
        {
          "url": "https://git.kernel.org/stable/c/ecbf3c45add30a0857414e156bdb9c79906f0ff6"
        },
        {
          "url": "https://git.kernel.org/stable/c/4cd92957e8f8cc4ebfe8a5d4203c14c592fde6b1"
        }
      ],
      "title": "wifi: nl80211: reject oversized EMA RNR lists",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-53182",
    "datePublished": "2026-06-25T08:38:56.654Z",
    "dateReserved": "2026-06-09T07:44:35.390Z",
    "dateUpdated": "2026-08-05T12:33:48.954Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…