CVE-2026-64176
CVE CVE-2026-64176EUVD EUVD-2026-45861Published 2026-07-19T15:41:00.000ZLast changed 2026-08-05T12:39:54.000ZCVSS 8.1
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as 7265D, rates are still encoded in version 1 format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but rather their PLCP value (e.g. 10 for 1 Mbps CCK rate.) While introducing v3 rates, I changed the driver from internally handling v1 rates and converting to v2, to internally handling v3 and converting to v1 or v2 according to the firmware. I accordingly changed the code in iwl_mvm_mac80211_idx_to_hwrate() to no longer have different values for different APIs. This was correct. However, I later reverted this part of the change, because it was reported that I had broken beacon rates, causing a FW assert/crash. This caused TX_CMD rates to be set incorrectly, potentially causing a warning when reported back from the device as having been used. Fix this (hopefully correctly now) by handling beacon rates in the TX_CMD that's embedded in the beacon template command separately. Restore iwl_mvm_mac80211_idx_to_hwrate() to return only the rate index, not PLCP value, fixing the real TX_CMD.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.34; c6c14c2b08e9c4c82e1ec39ef3e8b9ec845ac7fd; patch: 7.0.11; patch: 0; patch: 7.1; 6.18; 3592c0083fb29cca13cd9978b8844d58b4eff548 <6fe92651b44fd3cfc8dcfdaad0e82885c384dada; 3592c0083fb29cca13cd9978b8844d58b4eff548 <6b58a79f2cd98156856eb49e8b55db5facdd7e6d; 6.17.9 <6.18; 3592c0083fb29cca13cd9978b8844d58b4eff548 <fb84b5cbcaab3ca0f4e961d92a40ed7f3aac483b
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.