cbcvebase.
CVE-2026-23444
published 2026-04-03

CVE-2026-23444: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_skb() has three error paths, but only two of them free the skb. The first error path (ieee80211_tx_prepare() returning TX_DROP) does not free it, while invoke_tx_handlers() failure and the fragmentation check both do. Add kfree_skb() to the first error path so all three are consistent, and remove the now-redundant frees in callers (ath9k, mt76, mac80211_hwsim) to avoid double-free. Document the skb ownership guarantee in the function's kdoc.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 905ef207d5ed99ca64adfe39fba9ac46e434327a905ef207d5ed99ca64adfe39fba9ac46e434327a
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 5ef8ca1c164786da24169af155c1ca1ff1353cf85ef8ca1c164786da24169af155c1ca1ff1353cf8
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 9a779d1f480e83720b5384adf165604e7ee226bd9a779d1f480e83720b5384adf165604e7ee226bd
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < f77b51bcee7be2bb686b5f7a2d4a1921e4bdb9f4f77b51bcee7be2bb686b5f7a2d4a1921e4bdb9f4
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 3b4d27acafaeab478fd24f79ad6e593a892828b93b4d27acafaeab478fd24f79ad6e593a892828b9
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 06e769dddcbeb3baf2ce346273b53dd61fdbecf406e769dddcbeb3baf2ce346273b53dd61fdbecf4
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < 50f1b690b4868923fbd242298def2fb88662f10850f1b690b4868923fbd242298def2fb88662f108
linuxlinux>= 06be6b149f7e406bcf16098567f5a6c9f042bced < d5ad6ab61cbd89afdb60881f6274f74328af3ee9d5ad6ab61cbd89afdb60881f6274f74328af3ee9
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 3.13.1 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc7.1HIGH
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.