CVE-2026-68406
Received Received - Intake

Wi-Fi PMSR FTM Preamble Range Validation Bypass in Linux Kernel

Vulnerability report for CVE-2026-68406, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate PMSR FTM preamble range PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range. Reject out-of-range values before using them in the parser capability bit test using the policy. [drop unnecessary check]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper validation of PMSR FTM preamble range values in the wifi cfg80211 component. The parser accepts preamble values outside the defined nl80211 preamble range, which could lead to incorrect processing or potential security issues.

Detection Guidance

This vulnerability affects the Linux kernel's wifi configuration (cfg80211) and involves improper validation of PMSR FTM preamble ranges. Detection requires checking kernel versions and wifi driver behavior. No specific commands are provided in the context, but monitoring kernel logs for wifi-related errors or checking for out-of-range preamble values in network traffic may help identify exploitation attempts.

Impact Analysis

This vulnerability may allow attackers to send malformed wireless network requests, potentially causing system instability, crashes, or unauthorized access to network resources. Systems using affected Linux kernel versions could be at risk if not patched.

Mitigation Strategies

Apply the latest Linux kernel updates to patch the vulnerability. Monitor vendor advisories for specific kernel versions affected. Disable unnecessary wifi features if immediate patching is not possible. Ensure network monitoring for unusual preamble values in wifi traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68406. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart