PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23279 Linux CVE debrief

CVE-2026-23279 is a Linux kernel mac80211 bug that can crash systems using 802.11s mesh networking. A crafted Spectrum Management / Channel Switch action frame that matches the local Mesh ID and Mesh Configuration but omits the Mesh Channel Switch Parameters IE can trigger a NULL pointer dereference in mesh_rx_csa_frame(). The impact is denial of service through a kernel oops/panic risk, not code execution, based on the supplied record.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-22
Advisory published
2026-03-25
Advisory updated
2026-05-22

Who should care

Linux kernel maintainers, distribution security teams, and operators of systems that use Wi‑Fi mesh (802.11s) or mac80211-based wireless stacks should prioritize this issue. It is especially relevant for devices that accept peer links in mesh mode and may receive untrusted management frames from adjacent wireless peers.

Technical summary

According to the CVE record, mesh_rx_csa_frame() dereferences elems->mesh_chansw_params_ie without checking for NULL after mesh_matches_local() validates only the Mesh ID, Mesh Configuration, and Supported Rates IEs. If ieee802_11_parse_elems() does not find the Mesh Channel Switch Parameters IE (element ID 118), the pointer remains NULL and the unconditional access causes a NULL pointer dereference. The described trigger requires an established mesh peer link (PLINK_ESTAB) and a crafted SPECTRUM_MGMT/CHL_SWITCH action frame that omits the parameter IE while still matching the local mesh identifiers.

Defensive priority

Medium

Recommended defensive actions

  • Apply the Linux kernel patches referenced in the NVD record and your distribution's backport updates.
  • Prioritize updates on hosts that use 802.11s mesh or mac80211 mesh peering features.
  • Verify whether your deployed kernel version falls within the affected ranges listed by NVD, including the version branches starting at 3.13 and the 7.0-rc1 line.
  • Treat unexpected kernel oopses or reboots in mesh environments as a security signal and review logs for mac80211-related crashes.
  • If mesh networking is not required, disable or restrict mesh functionality to reduce exposure.

Evidence notes

The CVE description states that elems->mesh_chansw_params_ie is dereferenced in mesh_rx_csa_frame() without a prior NULL check, and that ieee802_11_parse_elems() leaves the pointer NULL when the Mesh Channel Switch Parameters IE is omitted. The supplied NVD record classifies the weakness as CWE-476 and provides patch references on git.kernel.org. The record also lists affected Linux kernel version ranges and a CVSS v3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23279 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23279

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23279 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23279

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/017c1792525064a723971f0216e6ef86a8c7af11

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/22a9adea7e26d236406edc0ea00b54351dd56b9c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2b5f282b1b7241ef624c3399a1cdff0bb1a3eeab

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/753ad20dcbe36b67088c7770d8fc357d7cc43e08

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/be8b82c567fda86f2cbb43b7208825125bb31421

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cc6d5a3c0a854aeae00915fc5386570c86029c60

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f061336f072ab03fd29270ae61fede46bf8fd69d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.