Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94467.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94467
Upstream
Published
2026-08-05T08:16:37Z
Modified
2026-08-28T17:48:06.831975055Z
Summary
CVE-2026-64574 affecting package kernel for versions less than 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: tear down new links on vif update error path

When ieee80211vifupdatelinks() adds new links it allocates a link container for each and calls ieee80211linkinit() (which registers the per-link debugfs files with file->privatedata pointing into the container) and ieee80211linksetup(). If the subsequent drvchangeviflinks() fails, the error path restores the old pointers and jumps to 'free', which frees the new containers but never removes their debugfs entries or stops the links. The debugfs files survive with file->privatedata dangling at the freed container, so a later open()+read() (e.g. link-1/txpower) dereferences freed memory in ieee80211ifread_link(), a use-after-free.

The removal path already dismantles links correctly via ieee80211teardownlinks(), which removes each link's keys and debugfs entries and calls ieee80211linkstop(); the add path on the error branch does not. Commit be1ba9ed221f ("wifi: mac80211: avoid weird state in error path") hardened this same error path for the link-removal case (newlinks == 0) but left the newly-added links' teardown unaddressed.

drvchangevif_links() can fail at runtime on MLO drivers (internal allocation / queue / firmware command failures).

Remove the new links' debugfs entries and stop them before freeing.

BUG: KASAN: slab-use-after-free in ieee80211ifreadlink (net/mac80211/debugfsnetdev.c:127) Read of size 8 at addr ffff888011290000 by task exploit/145 Call Trace: ... ieee80211ifreadlink (net/mac80211/debugfsnetdev.c:127) shortproxyread (fs/debugfs/file.c:373) vfsread (fs/readwrite.c:572) ksysread (fs/readwrite.c:716) dosyscall64 (arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) ... Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a RIP: 0010:ieee80211ifreadlink (net/mac80211/debugfsnetdev.c:127) Kernel panic - not syncing: Fatal exception

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94467.json"