PatchSiren cyber security CVE debrief
CVE-2026-46152 Linux CVE debrief
A race condition vulnerability in the Linux kernel's mac80211 Wi-Fi subsystem could cause packet misrouting or state corruption under concurrent receive conditions. The ieee80211_invoke_fast_rx() function was documented as safe for parallel RX, but used a static variable for its rx_result, causing concurrent callers to share and overwrite each other's results. This could lead to packets being incorrectly processed—either falling through to ieee80211_rx_8023() when they were already queued/consumed, or returning as queued when they should continue processing. The fix converts the static variable to an automatic (stack) variable so each invocation maintains independent state.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-07-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-07-29
Who should care
Linux system administrators running kernels with Wi-Fi mesh (802.11s) support; embedded/IoT device manufacturers using mac80211-based wireless stacks; security teams monitoring kernel networking subsystems for race condition vulnerabilities
Technical summary
The vulnerability exists in net/mac80211/rx.c in the ieee80211_invoke_fast_rx() function. A static enum rx_result res declaration caused all concurrent invocations to share the same storage location. Under parallel RX processing, one CPU could overwrite another's result between the ieee80211_rx_mesh_data() call and the subsequent switch statement on res. This could cause: (1) packets already queued or consumed by mesh processing to incorrectly fall through to ieee80211_rx_8023(), or (2) packets that should continue processing to return RX_QUEUED. The fix changes 'static enum rx_result res' to 'enum rx_result res', making it an automatic variable with per-invocation storage. The issue affects systems using 802.11s mesh networking where fast-RX optimizations are active.
Defensive priority
high
Recommended defensive actions
- Apply kernel updates from your Linux distribution that include the fixed mac80211 code
- Verify running kernel version is at or beyond the patched commits for your stable branch
- Monitor for mesh networking anomalies if running unpatched kernels with 802.11s mesh enabled
- Review system logs for unexpected packet processing errors in wireless interfaces
Evidence notes
Vulnerability disclosed via Linux kernel stable tree commits on 2026-05-28. The issue was a coding defect (incorrect use of static storage class) in a function explicitly documented as thread-safe for parallel execution. Multiple stable kernel branches received backported fixes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/03584528bfffb195e384698af9148b94e42e3f14
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1739fc31b4de06c5c78ce0741182770fb079091e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3ef44f96ccc3e06e059dec57842e366f0c4b1893
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7a5b81e0c87a075afd572f659d8eb68c9c4cd2ba
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e131562d6f2b958148c35c98831b007f47f0e3d3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.