wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
Published Jul 24, 2026
8.8
HIGHCVSS 3.1
EPSS 0.22%
Description
Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without checking that sta_mask is non-zero. When sta_mask is zero, ffs() returns 0 and the subtraction wraps to 0xFFFFFFFF, causing an out-of-bounds access on fw_id_to_link_sta[].
Add WARN_ON_ONCE(!ba_data->sta_mask) guards before each ffs() call, consistent with the existing check in iwl_mld_ampdu_rx_start().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.4
- Version 6.18.38StatusunaffectedConstraints<=6.18.*
- Version 7.1.3StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.4 · < 6.18.38
- ≥ 6.19 · < 7.1.3
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.53.1.el10_2
Fixed · RHSA-2026:65334
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.47.1.el9_8
Fixed · RHSA-2026:67150
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.47.1.el9_8
Fixed · RHSA-2026:67150
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.53.1.el10_2 | Fixed | RHSA-2026:65334 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.47.1.el9_8 | Fixed | RHSA-2026:67150 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.47.1.el9_8 | Fixed | RHSA-2026:67150 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-64255 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506782 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48664 Advisory
- https://git.kernel.org/stable/c/1de92789ce31e46fa7e7d8e89c90b19cdb1c103b Patch
- https://git.kernel.org/stable/c/f056fc2b927448d37eca6b6cacc3d1b0f67b20d2 Patch
- https://git.kernel.org/stable/c/fe7f339f63c9dc4ca546ed7ac38ba4bb3a99dcfc Patch
- https://lore.kernel.org/linux-cve-announce/2026072420-CVE-2026-64255-f09c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64255
- https://www.cve.org/CVERecord?id=CVE-2026-64255
Change history (0)
No recorded changes yet.