cbcvebase.
CVE-2026-31394
published 2026-04-03

CVE-2026-31394: In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_chan_bw_change() iterates all stations and accesses link->reserved.oper via sta->sdata->link[link_id]. For stations on AP_VLAN interfaces (e.g. 4addr WDS clients), sta->sdata points to the VLAN sdata, whose link never participates in chanctx reservations. This leaves link->reserved.oper zero-initialized with chan == NULL, causing a NULL pointer dereference in __ieee80211_sta_cap_rx_bw() when accessing chandef->chan->band during CSA. Resolve the VLAN sdata to its parent AP sdata using get_bss_sdata() before accessing link data. [also change sta->sdata in ARRAY_SIZE even if it doesn't matter]

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= b27512368591fc959768df1f7dacf2a96b1bd036 < 65c25b588994dd422fea73fa322de56e1ae4a33b65c25b588994dd422fea73fa322de56e1ae4a33b
linuxlinux>= b27512368591fc959768df1f7dacf2a96b1bd036 < 5a86d4e920d9783a198e39cf53f0e410fba5fbd65a86d4e920d9783a198e39cf53f0e410fba5fbd6
linuxlinux>= b27512368591fc959768df1f7dacf2a96b1bd036 < 3c6629e859a2211a1fbb4868f915413f80001ca53c6629e859a2211a1fbb4868f915413f80001ca5
linuxlinux>= b27512368591fc959768df1f7dacf2a96b1bd036 < 672e5229e1ecfc2a3509b53adcb914d8b024a853672e5229e1ecfc2a3509b53adcb914d8b024a853
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 6.11 < 6.12.786.12.78
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-lowlatency
ubuntulinux-lowlatency-hwe-6.8
ubuntulinux-nvidia

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.