cbcvebase.
CVE-2026-23336
published 2026-03-25

CVE-2026-23336: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() There is a use-after-free…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() There is a use-after-free error in cfg80211_shutdown_all_interfaces found by syzkaller: BUG: KASAN: use-after-free in cfg80211_shutdown_all_interfaces+0x213/0x220 Read of size 8 at addr ffff888112a78d98 by task kworker/0:5/5326 CPU: 0 UID: 0 PID: 5326 Comm: kworker/0:5 Not tainted 6.19.0-rc2 #2 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Workqueue: events cfg80211_rfkill_block_work Call Trace: dump_stack_lvl+0x116/0x1f0 print_report+0xcd/0x630 kasan_report+0xe0/0x110 cfg80211_shutdown_all_interfaces+0x213/0x220 cfg80211_rfkill_block_work+0x1e/0x30 process_one_work+0x9cf/0x1b70 worker_thread+0x6c8/0xf10 kthread+0x3c5/0x780 ret_from_fork+0x56d/0x700 ret_from_fork_asm+0x1a/0x30 The problem arises due to the rfkill_block work is not cancelled when wiphy is being unregistered. In order to fix the issue cancel the corresponding work in wiphy_unregister(). Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < 82a35356b5c1f75fe6a8a561db44e8d0e49da8f982a35356b5c1f75fe6a8a561db44e8d0e49da8f9
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < b2e9626a9d16b9bbbd06498c9e73c93be354dc7ab2e9626a9d16b9bbbd06498c9e73c93be354dc7a
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < eeea8da43ab86ac0a6b9cec225eec91564346940eeea8da43ab86ac0a6b9cec225eec91564346940
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < fa18639deab4a3662d543200c5bfc29bf4e23173fa18639deab4a3662d543200c5bfc29bf4e23173
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < 57e39fe8da573435fa35975f414f4dc17d9f844957e39fe8da573435fa35975f414f4dc17d9f8449
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < 584279ad9ff1e8e7c5494b9fce286201f7d1f9e2584279ad9ff1e8e7c5494b9fce286201f7d1f9e2
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < cd2f52944c7b95dcdfe0d87f385a2d96458a3ae5cd2f52944c7b95dcdfe0d87f385a2d96458a3ae5
linuxlinux>= 1f87f7d3a3b42b20f34cb03f0fd1a41c3d0e27f3 < 767d23ade706d5fa51c36168e92a9c5533c351a1767d23ade706d5fa51c36168e92a9c5533c351a1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 2.6.31 < 6.1.1676.1.167
linuxlinux_kernel>= 2.6.31.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa5.9MEDIUM
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.