| Summary | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: advance loop vars in cfg80211_merge_profile() cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS cfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem) but never advances mbssid_elem or sub_elem inside the body. Each Advance both mbssid_elem and sub_elem to the just-consumed continuation A specially-crafted malicious beacon can take advantage of this bug |
|---|---|
| Publication Date | July 20, 2026, 1:17 a.m. |
| Registration Date | July 20, 2026, 4:20 a.m. |
| Last Update | July 20, 2026, 1:17 a.m. |