KernelScan.io

HIGH Introduced in 3.2

mac80211 TdlsOper Bypass

CVE-2026-98332

CVSS 7.7 / 10.0 KernelScan AI

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: only operate on TDLS peers in the TDLS code ieee80211_tdls_oper() can operate on the AP station, which then yields various warnings when the AP station is removed then or at a later point in time after being confused for a TDLS peer. Always check that the station is a TDLS peer.

02

Engine v0.7.0

Risk summary

A local attacker with CAP_NET_ADMIN (obtainable via user namespaces on default configurations) can issue TDLS operations targeting the AP station instead of a TDLS peer, corrupting or removing the AP station and potentially causing use-after-free memory corruption. Systems with WiFi hardware supporting TDLS and unprivileged user namespaces enabled are at risk.

Affectednet/mac80211/tdls.c (mac80211 WiFi TDLS)

Vulnerability analysis

The TDLS operation handler in the mac80211 WiFi subsystem can operate on the AP station — the access point the device is associated with — instead of only on TDLS peer stations, because it fails to verify that the target station is actually a TDLS peer before performing operations such as teardown or link disable. This can corrupt the AP station's state or cause it to be incorrectly removed, leading to kernel warnings and potential memory corruption when the station is accessed afterward. The fix adds a validation check at the entry point of the TDLS operation handler to reject any station that is not a TDLS peer, and applies a similar check in the TDLS management setup path. The vulnerability is reachable from a local process through the nl80211 netlink interface, which requires CAP_NET_ADMIN — obtainable in a user namespace on systems where unprivileged user namespaces are enabled — and requires WiFi hardware with TDLS support.

03

BranchIntroducedFixed inPatch commit
7.23.27.2.80cd452ccaa5c
mainline3.27.3-rc46f0a100df853