7.8
CVE-2026-23185
- EPSS 0.13%
- Veröffentlicht 14.02.2026 16:27:14
- Zuletzt bearbeitet 15.07.2026 02:18:39
- Erkennungen
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.17 < 6.18.10
Linux ≫ Linux Kernel Version 6.19 Update rc1
Linux ≫ Linux Kernel Version 6.19 Update rc2
Linux ≫ Linux Kernel Version 6.19 Update rc3
Linux ≫ Linux Kernel Version 6.19 Update rc4
Linux ≫ Linux Kernel Version 6.19 Update rc5
Linux ≫ Linux Kernel Version 6.19 Update rc6
Linux ≫ Linux Kernel Version 6.19 Update rc7
Linux ≫ Linux Kernel Version 6.19 Update rc8
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.027 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-772 Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
https://git.kernel.org/stable/c/9b9f52f052f4953fecd2190ae2dde3aa76d10962
https://git.kernel.org/stable/c/5ff641011ab7fb63ea101251087745d9826e8ef5
https://bugzilla.redhat.com/show_bug.cgi?id=2439925
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23185.json
https://access.redhat.com/security/cve/CVE-2026-23185