CVE-2026-23185
Published: Feb 14, 2026
Modified: May 11, 2026
CVSS v3.1
7.8
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 9748ad82a9d92b036ff3115207e36e2b9932e354 - < 9b9f52f052f4953fecd2190ae2dde3aa76d10962affected 9748ad82a9d92b036ff3115207e36e2b9932e354 - < 5ff641011ab7fb63ea101251087745d9826e8ef5 |
Linux | Linux | affected 6.17unaffected 0 - < 6.17unaffected 6.18.10 - <= 6.18.*unaffected 6.19 - <= * |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now