CVE-2026-23396NULL Pointer Dereference in Linux

Severity
8.2HIGH
No vector
EPSS
0.0%
top 90.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateApr 20

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() unconditionally dereferences ie->mesh_config to compare mesh configuration parameters. When called from mesh_rx_csa_frame(), the parsed action-frame elements may not contain a Mesh Configuration IE, leaving ie->mesh_config NULL and triggering a kernel NULL pointer dereference. The other two callers are already safe: - ieee80211_mesh_rx_bcn_presp() che

Affected Packages5 packages

Linuxlinux/linux_kernel2.6.266.1.167+4
Debianlinux/linux_kernel< 6.19.10-1
CVEListV5linux/linux2e3c8736820bf72a8ad10721c7e31d36d4fa7790c1e3f2416fb27c816ce96d747d3e784e31f4d95c+6
debiandebian/linux< linux 6.19.10-1 (forky)

🔴Vulnerability Details

4
VulDB
Linux Kernel up to 7.0-rc4 net/mac80211/mesh.c mesh_matches_local null pointer dereference (EUVD-2026-16154 / WID-SEC-2026-0879)2026-04-20
GHSA
GHSA-w4qg-rh8m-6c8q: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() unco2026-03-26
OSV
CVE-2026-23396: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() uncond2026-03-26
OSV
wifi: mac80211: fix NULL deref in mesh_matches_local()2026-03-26

📋Vendor Advisories

3
Red Hat
kernel: wifi: mac80211: fix NULL deref in mesh_matches_local()2026-03-26
Microsoft
wifi: mac80211: fix NULL deref in mesh_matches_local()2026-03-10
Debian
CVE-2026-23396: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...2026

🕵️Threat Intelligence

58
Wiz
CVE-2025-68476 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-23356 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-1801 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-2303 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-23266 Impact, Exploitability, and Mitigation Steps | Wiz