cbcvebase.
CVE-2026-23135
published 2026-02-14

CVE-2026-23135: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dma_free_coherent() pointer dma_alloc_coherent() allocates a DMA mapped…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dma_free_coherent() pointer dma_alloc_coherent() allocates a DMA mapped buffer and stores the addresses in XXX_unaligned fields. Those should be reused when freeing the buffer rather than the aligned addresses.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 36e0bc5e8b282564906fca636c4ebc99814de4e736e0bc5e8b282564906fca636c4ebc99814de4e7
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 24585a13c41ea7253ee59aac74441fb570f5824a24585a13c41ea7253ee59aac74441fb570f5824a
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 4846b32be324f4dd3653f38a3f69c049543d52ae4846b32be324f4dd3653f38a3f69c049543d52ae
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < bb97131fbf9b708dd9616ac2bdc793ad102b5c48bb97131fbf9b708dd9616ac2bdc793ad102b5c48
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.3 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-gcp-fips
ubuntulinux-gke

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.