CVE-2026-23246Disclosure(linux / linux_kernel)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the ML Reconfiguration element (control & 0x000f), so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS (15) elements, so index 15 is out-of-bounds. Skip subelements with link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds write.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 3Technical Details · 2026-03-23: 103-1803-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure2Patch1
2026-03-231
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23246 Bounds-Check Vulnerability in Linux Kernel mac80211 Wireless Subsystem https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23246

    Post summary

    A bounds‑check vulnerability in the Linux kernel mac80211 wireless subsystem (CVE-2026-23246) has been announced, but details are limited to a brief description and a link to a vulnerability database.

    0000140
    4.0K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🧯 Bounds checks in mac80211: the Linux equivalent of not letting your kid drive. CVE-2026-23246 shows how one “legal” index can turn into a stack OOB write. https://windowsforum.com/threads/cve-2026-23246-mac80211-mlo-fix-bounds-check-prevents-stack-oob-write.406530/ #LinuxKernelSecurity #Mac80211Vulnerability #MloWiFi #Cve202623246 https://t.co/T4jSovU3CX

    Post summary

    The tweet announces CVE‑2026‑23246, noting a stack OOB write vulnerability in Linux mac80211, but offers no PoC, exploit, or patch details.

    000002
    1.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23246 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the M… https://www.cve.org/CVERecord?id=CVE-2026-23246

    Post summary

    The CVE-2026-23246 in the Linux kernel has been resolved with a patch, and the text provides a brief technical summary of the defect and a link to the CVE record.

    00000197
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23246 - wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration Intel Report: https://ift.tt/cKrq0uL

    Post summary

    The tweet announces CVE‑2026‑23246, describing a bounds‑check issue in mac80211, and links to an Intel report without providing PoC, exploit code, or patch information.

    0000025
    335 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.5--
OSlinuxlinux_kernel7.0--

Explore more