wifi: radiotap: reject radiotap with unknown bits
Published Mar 25, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.12%
Description
The radiotap parser is currently only used with the radiotap namespace (not with vendor namespaces), but if the undefined field 18 is used, the alignment/size is unknown as well. In this case, iterator->_next_ns_data isn't initialized (it's only set for skipping vendor namespaces), and syzbot points out that we later compare against this uninitialized value.
Fix this by moving the rejection of unknown radiotap fields down to after the in-namespace lookup, so it will really use iterator->_next_ns_data only for vendor namespaces, even in case undefined fields are present.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.34StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.34
- Version 5.10.253StatusunaffectedConstraints<=5.10.*
- Version 5.15.203StatusunaffectedConstraints<=5.15.*
- Version 6.1.167StatusunaffectedConstraints<=6.1.*
- Version 6.12.77StatusunaffectedConstraints<=6.12.*
- Version 6.18.17StatusunaffectedConstraints<=6.18.*
- Version 6.19.7StatusunaffectedConstraints<=6.19.*
- Version 6.6.130StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.34.1 · < 5.10.253
- ≥ 5.11 · < 5.15.203
- ≥ 5.16 · < 6.1.167
- ≥ 6.2 · < 6.6.130
- ≥ 6.7 · < 6.12.77
- ≥ 6.13 · < 6.18.17
- ≥ 6.19 · < 6.19.7
- 2.6.34
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-23367 Vendor Advisory
- https://git.kernel.org/stable/c/129c8bb320a7cef692c78056ef8e89a2a12ba448 Patch
- https://git.kernel.org/stable/c/2a60c588d5d39ad187628f58395c776a97fd4323 Patch
- https://git.kernel.org/stable/c/2f8ceeba670610d66f77def32011f48de951d781 Patch
- https://git.kernel.org/stable/c/6f80f6a60f5d87e5de5fb2732751fce799991c24 Patch
- https://git.kernel.org/stable/c/703fa979badbba83d31cd011606d060bfb8b0d1d Patch
- https://git.kernel.org/stable/c/c854758abe0b8d86f9c43dc060ff56a0ee5b31e0 Patch
- https://git.kernel.org/stable/c/d1d1d3c50095928624a95b67a6d7ccc3a18f2215 Patch
- https://git.kernel.org/stable/c/e664971759a0e5570b50c6592e58a7f97d55e992 Patch
- https://lore.kernel.org/linux-cve-announce/2026032540-CVE-2026-23367-6e44@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-23367
- https://www.cve.org/CVERecord?id=CVE-2026-23367
Change history (0)
No recorded changes yet.