CVE-2026-23185: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mloscanstartwk
mloscanstartwk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to.
This can cause an init-after-queue issue: if, for example, the work was queued and then drvchangeinterface got executed.
This can also cause use-after-free: if the work is executed after the vif is freed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23185?
The severity of CVE-2026-23185 is categorized as moderate due to potential impacts on wireless connection stability.
How do I fix CVE-2026-23185?
To fix CVE-2026-23185, update your Linux kernel to the latest stable version where the vulnerability has been patched.
What systems are affected by CVE-2026-23185?
CVE-2026-23185 affects the Linux kernel with the iwlwifi driver related to wireless networking.
What are the consequences of CVE-2026-23185?
The consequences of CVE-2026-23185 may include wireless disconnection issues that are not handled properly.
Is CVE-2026-23185 being actively exploited?
As of now, there is no public information indicating that CVE-2026-23185 is being actively exploited in the wild.