Junglewise Threat Intelligence

CVE-2026-23185: Linux Kernel iwlwifi use-after-free in MLO scan handling

CVE-2026-23185 · Severity: high · CVSS 7.8 · Published 2026-02-14

Technologies: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Linux Kernel, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat, Linux.

Executive brief

A vulnerability exists in the Linux kernel's Intel Wi-Fi driver (iwlwifi) that could lead to a system crash or unauthorized memory access. The issue occurs when a specific background scanning task is not properly stopped during a network disconnection, potentially allowing the system to attempt to use memory that has already been cleared. This could impact system stability and availability for users with affected Intel wireless hardware.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel 'iwlwifi' driver within the Multi-Link Operation (MLO) implementation. The root cause is a failure to cancel the 'mlo_scan_start_wk' delayed work item during interface disconnection or state changes. If the work item is queued and subsequently executed after the virtual interface (vif) has been freed, it results in a UAF condition. Additionally, this can trigger an 'init-after-queue' issue if 'drv_change_interface' is executed while the work is pending. The vulnerability is resolved by ensuring 'wiphy_delayed_work_cancel' is called for 'mlo_scan_start_wk' in the 'iwl_mld_move_sta_state_down' path.

Affected products

  • Linux Linux Kernel 9748ad82a9d9 to 5ff641011ab7fb63ea101251087745d9826e8ef5
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 10

Timeline

  • 2026-01-29: other: Patch authored by Intel
  • 2026-02-14: advisory: NVD publication date
  • 2026-02-14: disclosed: Upstream Linux CVE announcement

References

Related threats