CVE-2026-64515
Linux Kernel Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-64515 is a heap buffer overread vulnerability in the Linux kernel's mac80211 Wi-Fi subsystem, specifically in the Multi-Link Element (MLE) defragmentation routine. The flaw was published on July 25, 2026, and affects Linux kernel versions from 6.9 up to (but not including) the patched stable releases. Fixed versions include 6.12.92, 6.18.34, 7.0.11, and 7.1. The CVSS score has not been formally assigned, but Feedly estimates the severity as Medium (GitHub Advisory, Feedly).

Detalhes técnicos

The root cause is an incorrect pointer handling in the mac80211 MLE defragmentation routine (CWE not formally assigned; consistent with CWE-125: Out-of-bounds Read). When a reconf or EPCS multi-link element is contained in a non-transmitted profile, the defragmentation function is called with a pointer to the defragmented copy but is passed the original (non-defragmented) elements. This causes two failure modes: if defragmentation was originally needed, the routine cannot locate the correct data; and if the original frame resides at a higher memory address, the parser may overread heap memory into the new defragmentation buffer before halting. The fix tracks the container alongside the pointer and unifies the two near-identical defragmentation routines (GitHub Advisory, Feedly).

Impacto

Successful exploitation allows an unauthenticated attacker within wireless range to trigger a heap buffer overread during 802.11 MLE defragmentation processing, potentially disclosing sensitive kernel memory contents. The primary impact is a confidentiality breach — kernel memory may be leaked to an attacker — while integrity and availability are not directly affected under normal exploitation conditions. The scope is limited to Linux systems with Wi-Fi interfaces using the mac80211 subsystem that are exposed to untrusted wireless networks (Feedly).

Mitigação e soluções alternativas

Update the Linux kernel to a patched version: 6.12.92, 6.18.34, 7.0.11, or 7.1 and later. The corresponding upstream fix commits are 1f573e17bcb7, 55c479aae99b, 722b3f86df80, and a74e893f30db (GitHub Advisory). If immediate patching is not feasible, restrict wireless interface exposure to trusted networks and implement network segmentation to reduce the attack surface of Wi-Fi-enabled Linux systems (Feedly).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado Linux Kernel Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-64530CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-uki-virt-addons
NãoSimJul 26, 2026
CVE-2026-64515HIGH8.3
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NãoSimJul 25, 2026
CVE-2026-17523HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-internal
NãoNãoJul 27, 2026
CVE-2024-14040HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NãoSimJul 26, 2026
CVE-2026-64535NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k
NãoSimJul 27, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades