๐Ÿ” CVE Alert

CVE-2026-23185

HIGH 7.8

wifi: iwlwifi: mld: cancel mlo_scan_start_wk

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
4th

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 14, 2026
Last Updated Apr 3, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
9748ad82a9d92b036ff3115207e36e2b9932e354 < 9b9f52f052f4953fecd2190ae2dde3aa76d10962 9748ad82a9d92b036ff3115207e36e2b9932e354 < 5ff641011ab7fb63ea101251087745d9826e8ef5
Linux / Linux
6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9b9f52f052f4953fecd2190ae2dde3aa76d10962 git.kernel.org: https://git.kernel.org/stable/c/5ff641011ab7fb63ea101251087745d9826e8ef5