Junglewise Threat Intelligence

CVE-2026-23420: Linux Kernel improper locking in TI wlcore Wi-Fi driver

CVE-2026-23420 · Severity: medium · CVSS 5.5 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A locking error was identified in the Linux kernel's TI wlcore Wi-Fi driver. This flaw could allow a local user to cause a system crash or instability (denial of service) due to improper synchronization during power management operations. The issue has been resolved in recent kernel updates.

Technical details

A locking bug (CWE-667) was identified in 'drivers/net/wireless/ti/wlcore/main.c' within the Linux kernel. In the 'wl1271_op_resume' function, the code failed to acquire 'wl->mutex' before attempting to perform operations that required it, or attempted to unlock it without a prior lock. This race condition/synchronization error was detected by the Clang thread-safety analyzer. An attacker with local access could potentially trigger this flaw to cause a kernel panic or deadlock, resulting in a denial of service. Patches have been backported to multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, and 6.6.y.

Affected products

  • Linux Linux Kernel 4.19 to 6.18.17, 6.19 to 6.19.7, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-04-03: disclosed
  • 2026-03-03: patched: Initial patch committed to mainline kernel.

References

Related threats