CVE-2026-90343
CVE CVE-2026-90343EUVD EUVD-2026-82004Published 2026-09-17T16:08:53.000ZLast changed 2026-09-18T17:54:45.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardown PMSR request teardown must abort active measurements while the wireless_dev is still present in the driver. cfg80211_leave_locked() and cfg80211_stop_pd() already do this before invoking the driver's stop callback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not. Those helpers are also called directly by nl80211, rfkill shutdown, and wireless_dev unregister paths. If one of these paths stops a P2P device or NAN interface with a pending request, it removes the mac80211 subinterface from the driver first. Subsequent request cleanup cannot reach the lower driver's abort callback, but cfg80211 frees the request regardless. Driver state can then retain a stale request and use it when it later reports a result. Call cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN interface. This keeps lower-driver request state and cfg80211 request ownership in sync for all of the helpers' callers.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <6c5fc504d0d6934132637aa3db4b9b58148eaa78; 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <db3439ad11ac5e52decdefe784c98b21c3757848; patch: 7.2.6; patch: 6.18.52; 9bb7e0f24e7e7d00daa1219b14539e2e602649b2 <7a22cbc6c6bdd3c3811b4ce13875685c520f94de; 5.0; patch: 7.3-rc1; patch: 0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.