In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: drop stray 'static' from fast-RX rx_result
ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but
its per-invocation rx_result is declared static. Concurrent callers then
share one instance and can overwrite each other's result between
ieee80211_rx_mesh_data() and the switch on res.
That can make a packet that was queued or consumed by
ieee80211_rx_mesh_data() fall through into ieee80211_rx_8023(), or make
a packet that should continue return as queued.
Make res an automatic variable so each invocation keeps its own result.
References
Configurations
Configuration 1 (hide)
|
History
09 Jun 2026, 21:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/03584528bfffb195e384698af9148b94e42e3f14 - Patch | |
| References | () https://git.kernel.org/stable/c/1739fc31b4de06c5c78ce0741182770fb079091e - Patch | |
| References | () https://git.kernel.org/stable/c/3ef44f96ccc3e06e059dec57842e366f0c4b1893 - Patch | |
| References | () https://git.kernel.org/stable/c/7a5b81e0c87a075afd572f659d8eb68c9c4cd2ba - Patch | |
| References | () https://git.kernel.org/stable/c/e131562d6f2b958148c35c98831b007f47f0e3d3 - Patch | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
|
| First Time |
Linux linux Kernel
Linux |
30 May 2026, 11:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
28 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 10:16
Updated : 2026-06-09 21:06
NVD link : CVE-2026-46152
Mitre link : CVE-2026-46152
CVE.ORG link : CVE-2026-46152
JSON object : View
Products Affected
linux
- linux_kernel
CWE
