← All Advisories

CVE-2026-97432

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97432

Key Details

CVECVE-2026-97432
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix P2P-Device binding handling

Our binding handling for P2P-Device can run into the following

scenario, as observed by our testing:

- a station interface is connected on some channel

- the P2P-Device does a remain-on-channel (ROC) on that channel

- the ROC ends, and the P2P-Device is removed from the binding,

but the phy_ctxt pointer is left around as a PHY cache so we

don't need to recalibrate to the channel again and again in

case it's not shared

- a binding update by the station interface, even a removal,

will re-add the P2P-Device to the binding

- the P2P-Device is removed, which removes the PHY context, but

it's still in the binding so the firmware crashes

Since the P2P device is removed from the binding and only re-

added by unrelated code, but we want to keep the phy_ctxt around

as a cache for future ROC usage, fix it by adding a boolean that

indicates whether or not the P2P-Device should be added to the

binding, and handle that in the binding iterator. That way, the

station interface cannot re-add the P2P-Device to the binding

when that isn't active. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97432
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97432