CVE-2026-68197
Received Received - Intake

NULL Dereference in mwifiex WiFi Driver

Vulnerability report for CVE-2026-68197, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc->bcn_ht_cap being present, but then dereferences a different pointer, bss_desc->bcn_ht_oper: if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) && bss_desc->bcn_ht_cap && ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param)) bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first. Guard on the pointer that is actually dereferenced. Found by 0sec automated security-research tooling (https://0sec.ai).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the Linux kernel's mwifiex Wi-Fi driver. It occurs when a TDLS link is set up while connected to an access point (AP) that advertises HT-capabilities but no HT-operation information. The driver incorrectly assumes both pieces of data are present, leading to a kernel crash.

Detection Guidance

This vulnerability is specific to the Linux kernel's mwifiex WiFi driver and requires kernel memory corruption to trigger. Detection typically involves checking kernel logs for crashes or examining the mwifiex driver code for HT capabilities mismatches. No direct network commands detect this flaw as it is a driver-level issue.

Impact Analysis

If exploited, this vulnerability could cause a system crash, leading to denial of service. It requires an attacker to be within Wi-Fi range to trigger the issue by manipulating AP beacon frames, making it a local network threat rather than a remote one.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for CVE-2026-68197. If immediate patching is not possible, disable TDLS functionality or avoid connecting to APs that advertise HT capabilities without HT operation elements.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68197. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart