Use-After-Free Vulnerability in Linux Kernel's cfg80211 Module
CVE-2026-68414

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68414?

A vulnerability in the Linux kernel, specifically within the cfg80211 module, leads to a use-after-free condition when concurrently handling scheduled scan requests and device unregistration. This issue arises from improper management of queued work items, potentially allowing an attacker to exploit freed memory states. The improper synchronization between removing existing scheduled scans and unregistering devices could lead to dereferencing invalid memory, potentially affecting system stability and security. Developers are advised to ensure proper cancellation of queued work items during device unregistration to mitigate risks.

Affected Version(s)

Linux 807f8a8c300435d5483e8d78df9dcdbc27333166 < 3368457b4871ae8f0f88d19c9a3e6270e850ede6

Linux 807f8a8c300435d5483e8d78df9dcdbc27333166 < 308ffdf575560d7e7b8b21f1e3ca6276630f73bf

Linux 807f8a8c300435d5483e8d78df9dcdbc27333166 < 9293574ac208d18c11073538851fb69355beb3b5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.