CVE-2026-64515
CVE CVE-2026-64515EUVD EUVD-2026-48859Published 2026-07-25T09:14:42.000ZLast changed 2026-08-05T12:42:32.000ZCVSS 8.3
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix MLE defragmentation If either reconf or EPCS multi-link element (MLE) is contained in a non-transmitted profile, the defragmentation routine is called with a pointer to the defragmented copy, but the original elements. This is incorrect for two reasons: - if the original defragmentation was needed, it will not find the correct data - if the original frame is at a higher address, the parsing will potentially overrun the heap data (though given the layout of the buffers, only into the new defragmentation buffer, and then it has to stop and fail once that's filled with copied data. Fix it by tracking the container along with the pointer and in doing so also unify the two almost identical defragmentation routines.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff <1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4; patch: 6.18.34; patch: 7.0.11; patch: 7.1; 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff <a74e893f30db64cdce0fc7a96d3baa417bcd55f5; 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff <55c479aae99b120489a432db9c717484e523dfd6; patch: 6.12.92; 4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff <722b3f86df80644463d29fe5451e30a617f74500; 6.9; patch: 0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.