cbcvebase.
CVE-2026-46125
published 2026-05-28

CVE-2026-46125: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparation fails for…

PriorityP346high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.30%
22.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparation fails for MLO connections, then the interface is completely reset to non-MLD. In this case, we must not keep the station since it's related to the link of the vif being removed. Delete an existing station. Any "new_sta" is already being removed, so that doesn't need changes. This fixes a use-after-free/double-free in debugfs if that's enabled, because a vif going from MLD (and to MLD, but that's not relevant here) recreates its entire debugfs.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < 18fed0a209500bfea5c4c08609ec93855e4e500b18fed0a209500bfea5c4c08609ec93855e4e500b
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < fe75fa1ac9a92990f7fc3d34b17808fd933071b2fe75fa1ac9a92990f7fc3d34b17808fd933071b2
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < afcbaed89cdc1a001b43270cbf5394bb4804270aafcbaed89cdc1a001b43270cbf5394bb4804270a
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < 9e28654f79f443bca9b29ff3ae7cf18abfba58a09e28654f79f443bca9b29ff3ae7cf18abfba58a0
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < 1c2b72ea89882aeb948340498391e69c58d466f11c2b72ea89882aeb948340498391e69c58d466f1
linuxlinux>= 81151ce462e533551f3284bfdb8e0f461c9220e6 < 283fc9e44ff5b5ac967439b4951b80bd4299f4e4283fc9e44ff5b5ac967439b4951b80bd4299f4e4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.0 < 6.1.1766.1.176
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.886.12.88
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.