๐Ÿ” CVE Alert

CVE-2026-23444

HIGH 7.8

wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_skb() has three error paths, but only two of them free the skb. The first error path (ieee80211_tx_prepare() returning TX_DROP) does not free it, while invoke_tx_handlers() failure and the fragmentation check both do. Add kfree_skb() to the first error path so all three are consistent, and remove the now-redundant frees in callers (ath9k, mt76, mac80211_hwsim) to avoid double-free. Document the skb ownership guarantee in the function's kdoc.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 3, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
06be6b149f7e406bcf16098567f5a6c9f042bced < 905ef207d5ed99ca64adfe39fba9ac46e434327a 06be6b149f7e406bcf16098567f5a6c9f042bced < 5ef8ca1c164786da24169af155c1ca1ff1353cf8 06be6b149f7e406bcf16098567f5a6c9f042bced < 9a779d1f480e83720b5384adf165604e7ee226bd 06be6b149f7e406bcf16098567f5a6c9f042bced < f77b51bcee7be2bb686b5f7a2d4a1921e4bdb9f4 06be6b149f7e406bcf16098567f5a6c9f042bced < 3b4d27acafaeab478fd24f79ad6e593a892828b9 06be6b149f7e406bcf16098567f5a6c9f042bced < 06e769dddcbeb3baf2ce346273b53dd61fdbecf4 06be6b149f7e406bcf16098567f5a6c9f042bced < 50f1b690b4868923fbd242298def2fb88662f108 06be6b149f7e406bcf16098567f5a6c9f042bced < d5ad6ab61cbd89afdb60881f6274f74328af3ee9
Linux / Linux
3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/905ef207d5ed99ca64adfe39fba9ac46e434327a git.kernel.org: https://git.kernel.org/stable/c/5ef8ca1c164786da24169af155c1ca1ff1353cf8 git.kernel.org: https://git.kernel.org/stable/c/9a779d1f480e83720b5384adf165604e7ee226bd git.kernel.org: https://git.kernel.org/stable/c/f77b51bcee7be2bb686b5f7a2d4a1921e4bdb9f4 git.kernel.org: https://git.kernel.org/stable/c/3b4d27acafaeab478fd24f79ad6e593a892828b9 git.kernel.org: https://git.kernel.org/stable/c/06e769dddcbeb3baf2ce346273b53dd61fdbecf4 git.kernel.org: https://git.kernel.org/stable/c/50f1b690b4868923fbd242298def2fb88662f108 git.kernel.org: https://git.kernel.org/stable/c/d5ad6ab61cbd89afdb60881f6274f74328af3ee9