CVE-2026-23040
published 2026-02-04CVE-2026-23040: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745…
PriorityP417medium7.6
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.8-1 (forky) | linux 6.18.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= a37a6f54439bf82b827a7072415d3a4afa4e12bd < 1251bbdb8f5b2ea86ca9b4268a2e6aa34372ab33 | 1251bbdb8f5b2ea86ca9b4268a2e6aa34372ab33 |
| linux | linux | >= a37a6f54439bf82b827a7072415d3a4afa4e12bd < 333418872bfecf4843f1ded7a4151685dfcf07d5 | 333418872bfecf4843f1ded7a4151685dfcf07d5 |
| linux | linux_kernel | >= 0 < 6.18.8-1 | 6.18.8-1 |
| linux | linux_kernel | >= 6.18.0 < 6.18.6 | 6.18.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.5/6.19-rc4 wifi mac80211_hwsim null pointer dereference (Nessus ID 297932 / WID-SEC-2026-0324)
vuldb·2026-04-30
CVE-2026-23040 [CRITICAL] Linux Kernel up to 6.18.5/6.19-rc4 wifi mac80211_hwsim null pointer dereference (Nessus ID 297932 / WID-SEC-2026-0324)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.5/6.19-rc4. This affects the function mac80211_hwsim of the component wifi. Performing a manipulation results in null pointer dereference.
This vulnerability was named CVE-2026-23040. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-4mqx-ggc6-9qj3: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is
ghsa_unreviewed·2026-02-04
CVE-2026-23040 GHSA-4mqx-ggc6-9qj3: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
OSV
CVE-2026-23040: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is f
osv·2026-02-04
CVE-2026-23040 CVE-2026-23040: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is f
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.
OSV
wifi: mac80211_hwsim: fix typo in frequency notification
osv·2026-02-04
CVE-2026-23040 wifi: mac80211_hwsim: fix typo in frequency notification
wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Red Hat
kernel: wifi: mac80211_hwsim: fix typo in frequency notification
vendor_redhat·2026-02-04·CVSS 7.6
CVE-2026-23040 [MEDIUM] CWE-476 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
kernel: wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Statement: The mac80211_hwsim virtual WiFi driver contains an incorrect frequency constant used when generating NAN discovery window notifications on the 5 GHz band that can lead to Null pointer deref. In mac80211_hwsim_nan_dw_start the driver calls ieee80211_get_channel with 5475 MHz when nan_curr_dw_band is NL80211_BAND_5GHZ. That frequency does not correspond to a valid channel in typical wiphy channe
Debian
CVE-2026-23040: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
vendor_debian·2026
CVE-2026-23040 [LOW] CVE-2026-23040: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: fix typo in frequency notification The NAN notification is for 5745 MHz which corresponds to channel 149 and not 5475 which is not actually a valid channel. This could result in a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.8-1)
sid: resolved (fixed in 6.18.8-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
bugzilla·2026-02-04
CVE-2026-23040 [MEDIUM] CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
CVE-2026-23040 kernel: wifi: mac80211_hwsim: fix typo in frequency notification
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026020438-CVE-2026-23040-1980@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18134 https://access.redhat.com/errata/RHSA-2026:18134
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18587 h
Wiz
CVE-2026-23040 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23040 CVE-2026-23040 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23040 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211_hwsim: fix typo in frequency notification
The NAN notification is for 5745 MHz which corresponds to channel 149
and not 5475 which is not actually a valid channel. This could result in
a NULL pointer dereference in cfg80211_next_nan_dw_notif.
Source : NVD
Published February 4, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-debug-modules-partner
kernel-rt-modules-partner
Sources
NVD
Deb
2026-02-04
Published