{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: fix tid_tx use-after-free on BA session stop  ieee80211_stop_tx_ba_cb() hands tid_tx to kfree_rcu() through ieee80211_remove_tid_tx(), and then reads tid_tx-\u003endp after dropping sta-\u003elock:  \tieee80211_remove_tid_tx(sta, tid);\t/* kfree_rcu(tid_tx, rcu_head) */ \t... \tspin_unlock_bh(\u0026sta-\u003elock);  \tif (start_txq) \t\tieee80211_agg_start_txq(sta, tid, false);  \tif (send_delba) \t\tieee80211_send_delba(..., tid_tx-\u003endp);  That read is not covered by an RCU read-side critical section, and it runs in preemptible process context: both callers hold the wiphy mutex, reaching it either from the ieee80211_ba_session_work() wiphy work or from ieee80211_sta_tear_down_BA_sessions() during station teardown. Softirqs can run in that window too, both from the local_bh_enable() that ends ieee80211_agg_start_txq() and from any interrupt exit, so the RCU callback can free tid_tx before the read.  Driving the function from a test module with the grace period forced into that window, KASAN reports the read, and the free arrives on the ordinary RCU softirq path:    BUG: KASAN: slab-use-after-free in ieee80211_stop_tx_ba_cb+0x3cd/0x400   Read of size 1 at addr ffff888002b9f52e by task kworker/0:1/10   [...]   Freed by task 57:    __kasan_slab_free+0x47/0x70    __rcu_free_sheaf_prepare+0x70/0x250    rcu_free_sheaf_nobarn+0x18/0x40    rcu_core+0x426/0x1310    handle_softirqs+0x144/0x590    __irq_exit_rcu+0xea/0x150    irq_exit_rcu+0x9/0x20    sysvec_apic_timer_interrupt+0x6b/0x80    asm_sysvec_apic_timer_interrupt+0x1a/0x20  send_delba is only set when tx_stop is set, which happens for AGG_STOP_LOCAL_REQUEST alone, so this is reached on local teardown - session idle timeout, PTK rekey, suspend, HW reconfig - and not from a peer's DELBA.  Read ndp into a local before the session is freed, while sta-\u003elock is still held. tid_tx-\u003endp has a single writer, in ieee80211_tx_ba_session_handle_start(), which cannot run concurrently here: both paths are serialised by the wiphy mutex, and the session is already marked HT_AGG_STATE_STOPPING at this point. tid_tx-\u003endp is also the only tid_tx dereference left after ieee80211_remove_tid_tx() in this function.  [move/change the comment a bit to be more general not just on ndp,  initialize ndp directly]",
  "id": "DEBIAN-CVE-2026-74489",
  "modified": "2026-09-14T16:47:35.242460776Z",
  "published": "2026-08-15T13:17:53.813Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-74489"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-74489"
  ]
}