CVE-2026-23185
published 2026-02-14CVE-2026-23185: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled on disconnection. In fact, it is not
canceled anywhere except in the restart cleanup, where we don't really
have to.
This can cause an init-after-queue issue: if, for example, the work was
queued and then drv_change_interface got executed.
This can also cause use-after-free: if the work is executed after the
vif is freed.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.10-1 (forky) | linux 6.18.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 9748ad82a9d92b036ff3115207e36e2b9932e354 < 9b9f52f052f4953fecd2190ae2dde3aa76d10962 | 9b9f52f052f4953fecd2190ae2dde3aa76d10962 |
| linux | linux | >= 9748ad82a9d92b036ff3115207e36e2b9932e354 < 5ff641011ab7fb63ea101251087745d9826e8ef5 | 5ff641011ab7fb63ea101251087745d9826e8ef5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.18.10-1 | 6.18.10-1 |
| linux | linux_kernel | >= 6.17 < 6.18.10 | 6.18.10 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
vendor_redhat·2026-02-14·CVSS 7.8
CVE-2026-23185 [HIGH] CWE-772 kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled on disconnection. In fact, it is not
canceled anywhere except in the restart cleanup, where we don't really
have to.
This can cause an init-after-queue issue: if, for example, the work was
queued and then drv_change_interface got executed.
This can also cause use-after-free: if the work is executed after the
vif is freed.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat E
Debian
CVE-2026-23185: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwi...
vendor_debian·2026·CVSS 7.8
CVE-2026-23185 [HIGH] CVE-2026-23185: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwi...
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.10-1)
sid: resolved (fixed in 6.18.10-1)
trixie: resolved
VulDB
Linux Kernel up to 6.18.9 wifi mlo_scan_start_wk use after free (EUVD-2026-5859 / Nessus ID 299114)
vuldb·2026-07-01·CVSS 7.8
CVE-2026-23185 [HIGH] Linux Kernel up to 6.18.9 wifi mlo_scan_start_wk use after free (EUVD-2026-5859 / Nessus ID 299114)
A vulnerability classified as critical was found in Linux Kernel up to 6.18.9. This vulnerability affects the function mlo_scan_start_wk of the component wifi. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-23185. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is advised.
OSV
CVE-2026-23185: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on
osv·2026-02-14·CVSS 7.8
CVE-2026-23185 [HIGH] CVE-2026-23185: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, where we don't really have to. This can cause an init-after-queue issue: if, for example, the work was queued and then drv_change_interface got executed. This can also cause use-after-free: if the work is executed after the vif is freed.
GHSA
GHSA-3jpp-f2wm-pcvv: In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled o
ghsa_unreviewed·2026-02-14
CVE-2026-23185 [HIGH] CWE-416 GHSA-3jpp-f2wm-pcvv: In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled o
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled on disconnection. In fact, it is not
canceled anywhere except in the restart cleanup, where we don't really
have to.
This can cause an init-after-queue issue: if, for example, the work was
queued and then drv_change_interface got executed.
This can also cause use-after-free: if the work is executed after the
vif is freed.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23185 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-23185 [HIGH] CVE-2026-23185 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23185 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled on disconnection. In fact, it is not
canceled anywhere except in the restart cleanup, where we don't really
have to.
This can cause an init-after-queue issue: if, for example, the work was
queued and then drv_change_interface got executed.
This can also cause use-after-free: if the work is executed after the
vif is freed.
Source : NVD
## 7.8
Score
Published February 14, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation
Bugzilla
CVE-2026-23185 kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
bugzilla·2026-02-14·CVSS 7.8
CVE-2026-23185 [HIGH] CVE-2026-23185 kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
CVE-2026-23185 kernel: wifi: iwlwifi: mld: cancel mlo_scan_start_wk
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: cancel mlo_scan_start_wk
mlo_scan_start_wk is not canceled on disconnection. In fact, it is not
canceled anywhere except in the restart cleanup, where we don't really
have to.
This can cause an init-after-queue issue: if, for example, the work was
queued and then drv_change_interface got executed.
This can also cause use-after-free: if the work is executed after the
vif is freed.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026021431-CVE-2026-23185-7d56@gregkh/T
https://git.kernel.org/stable/c/5ff641011ab7fb63ea101251087745d9826e8ef5https://git.kernel.org/stable/c/9b9f52f052f4953fecd2190ae2dde3aa76d10962https://access.redhat.com/security/cve/CVE-2026-23185https://bugzilla.redhat.com/show_bug.cgi?id=2439925https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23185.json
2026-02-14
Published