In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix MLE defragmentation
If either reconf or EPCS multi-link element (MLE) is contained in a non-transmitted profile, the defragmentation routine is called with a pointer to the defragmented copy, but the original elements.
This is incorrect for two reasons:
Fix it by tracking the container along with the pointer and in doing so also unify the two almost identical defragmentation routines.
Exploitability
AV:AAC:LPR:NUI:NScope
S:UImpact
C:HI:LA:H8.3/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H