CVE-2026-74488
Last modified
CVE-2026-74488 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each subframe it passes the subframe data pointer to mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the length of the A-MSDU parent, instead of rx_skb->len: rx_skb = __skb_dequeue(&list); rx_hdr = (struct rx_packet_hdr *)rx_skb->data; if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) && ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) { mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr, skb->len); } The parent is not a valid description of that buffer, and may not be valid memory at all. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each subframe it passes the subframe data pointer to mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the length of the A-MSDU parent, instead of rx_skb->len: rx_skb = __skb_dequeue(&list); rx_hdr = (struct rx_packet_hdr *)rx_skb->data; if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) && ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) { mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr, skb->len); } The parent is not a valid description of that buffer, and may not be valid memory at all. ieee80211_amsdu_to_8023s() ends with if (!reuse_skb) dev_kfree_skb(skb); and it only sets reuse_skb when the parent is linear, is not a head_frag, and is being consumed as the *last* subframe. So when the parent does not qualify for reuse it has already been freed, and the read of skb->len is a use-after-free. When it is reused, skb->len is the length of the last subframe, applied to every earlier subframe, which over-states the buffer whenever an earlier subframe is shorter. The callee cannot absorb a wrong length, because it derives its own ceiling from the value it is given. Each frame type computes ies_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN; and the element walk is then bounded entirely against that ceiling, for (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) { u8 ie_len = pos[1]; if (pos + 2 + ie_len > end) break; so a too-large len moves end past the end of the subframe and the walk reads and copies beyond it. The A-MSDU layout is chosen by the sender, which makes the difference between the last subframe and a shorter earlier one remotely selectable. Reaching this requires TDLS support in firmware and the TDLS ethertype on the subframe. The other caller, mwifiex_process_rx_packet(), is correct: it passes a pointer and a length that describe the same region of the RX buffer. Pass rx_skb->len, the length of the subframe actually being parsed.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < 707664027bb9307f7268eda403af7c4ccd9b8644; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < 3b02275833a0d3e6583627995d614fa99bdf364f; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < a1f0f7dc7eb15754e6931b433edb7beb754c996a; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < 25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < ece2ebb34247d573142617dfc534a9dc11ba59be; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < c9dcfe6b8b71369e1d732e2ff622c3696a2f032c; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < 5a21ab03829cb6d2682c127f22e2b9cd63b4393f; >= 776f742040ca5eb6242c60f29ac73d5752a5b621, < 99a948382af8a225e2d5e54a7052158cd6281cc6 |
| Linux | Linux | 4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74488?
How severe is CVE-2026-74488?
How do I fix CVE-2026-74488?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74482In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74483In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74484In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74485In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-74486In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74487In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74489In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-74490In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-74491In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74492In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-74493In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-74494In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74488?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
