Home

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.

PUBLISHED Reserved 2026-01-13 | Published 2026-02-14 | Updated 2026-02-14 | Assigner Linux

Product status

Default status
unaffected

9748ad82a9d92b036ff3115207e36e2b9932e354 (git) before 9b9f52f052f4953fecd2190ae2dde3aa76d10962
affected

9748ad82a9d92b036ff3115207e36e2b9932e354 (git) before 5ff641011ab7fb63ea101251087745d9826e8ef5
affected

Default status
affected

6.17
affected

Any version before 6.17
unaffected

6.18.10 (semver)
unaffected

6.19 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/9b9f52f052f4953fecd2190ae2dde3aa76d10962

git.kernel.org/...c/5ff641011ab7fb63ea101251087745d9826e8ef5

cve.org (CVE-2026-23185)

nvd.nist.gov (CVE-2026-23185)

Download JSON