In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such… (CVE-2026-64176)
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as 7265D, rates are still encoded in version 1 format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but rather their PLCP value (e.g. 10 for 1 Mbps CCK rate.) While introducing v3 rates, I changed the driver from internally handling v1 rates and converting to v2, to internally handling v3 and converting to v1 or v2 according to the firmware. I accordingly changed the code in iwl_mvm_mac80211_idx_to_hwrate() to no longer have different values for different APIs. This was correct. However, I later reverted this part of the change, because it was reported that I had broken beacon rates, causing a FW assert/crash. This caused TX_CMD rates to be set incorrectly, potentially causing a warning when reported back from the device as having been used. Fix this (hopefully correctly now) by handling beacon rates in the TX_CMD that's embedded in the beacon template command separately. Restore iwl_mvm_mac80211_idx_to_hwrate() to return only the rate index, not PLCP value, fixing the real TX_CMD.
AI Analysis
Technical Summary
The Linux kernel iwlwifi driver previously mishandled transmission rates on older devices that use version 1 rate encoding (PLCP values instead of standard rate indices). A change to handle version 3 rates internally caused incorrect TX_CMD rate settings, leading to potential firmware asserts or crashes. The fix involved separating beacon rate handling in the TX_CMD embedded in beacon templates and restoring the function iwl_mvm_mac80211_idx_to_hwrate() to return only rate indices rather than PLCP values, correcting the TX_CMD rate settings.
Potential Impact
Incorrect TX_CMD rate settings could cause warnings or firmware asserts/crashes on affected devices, potentially impacting wireless transmission stability or reliability. There is no indication of remote code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the handling of TX rates on old devices in the iwlwifi driver. Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly stated in the provided data; check the official Linux kernel advisories or vendor updates for the specific fixed version.
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such… (CVE-2026-64176)
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices On old devices such as 7265D, rates are still encoded in version 1 format, which doesn't use the CCK/OFDM rate index (0-3/0-7) but rather their PLCP value (e.g. 10 for 1 Mbps CCK rate.) While introducing v3 rates, I changed the driver from internally handling v1 rates and converting to v2, to internally handling v3 and converting to v1 or v2 according to the firmware. I accordingly changed the code in iwl_mvm_mac80211_idx_to_hwrate() to no longer have different values for different APIs. This was correct. However, I later reverted this part of the change, because it was reported that I had broken beacon rates, causing a FW assert/crash. This caused TX_CMD rates to be set incorrectly, potentially causing a warning when reported back from the device as having been used. Fix this (hopefully correctly now) by handling beacon rates in the TX_CMD that's embedded in the beacon template command separately. Restore iwl_mvm_mac80211_idx_to_hwrate() to return only the rate index, not PLCP value, fixing the real TX_CMD.
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel iwlwifi driver previously mishandled transmission rates on older devices that use version 1 rate encoding (PLCP values instead of standard rate indices). A change to handle version 3 rates internally caused incorrect TX_CMD rate settings, leading to potential firmware asserts or crashes. The fix involved separating beacon rate handling in the TX_CMD embedded in beacon templates and restoring the function iwl_mvm_mac80211_idx_to_hwrate() to return only rate indices rather than PLCP values, correcting the TX_CMD rate settings.
Potential Impact
Incorrect TX_CMD rate settings could cause warnings or firmware asserts/crashes on affected devices, potentially impacting wireless transmission stability or reliability. There is no indication of remote code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the handling of TX rates on old devices in the iwlwifi driver. Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly stated in the provided data; check the official Linux kernel advisories or vendor updates for the specific fixed version.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m7pm-g64q-7xf7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64176"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a82a4a8d598912a21a
Added to database: 07/19/2026, 19:38:16 UTC
Last enriched: 07/19/2026, 19:39:52 UTC
Last updated: 07/20/2026, 19:41:21 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.