CVE-2026-23040
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23040 is a NULL pointer dereference vulnerability in the Linux kernel's mac80211_hwsim Wi-Fi simulation driver, caused by a typo in a NAN (Neighbor Awareness Networking) frequency notification. The incorrect frequency value (5475 MHz instead of the correct 5745 MHz, corresponding to channel 149) is not a valid channel, which can trigger a NULL pointer dereference in cfg80211_next_nan_dw_notif. The vulnerability was published on February 4, 2026, and affects Linux kernel versions in the range from commit a37a6f54439bf82b827a7072415d3a4afa4e12bd up to the patched commits. It is estimated as Medium severity with an EPSS score of 0.000240 (Feedly, EUVD).

Technical details

The root cause is a simple typographical error in the mac80211_hwsim kernel module where the NAN dual-band notification frequency is hardcoded as 5475 MHz instead of the correct 5745 MHz (channel 149, CWE-476: NULL Pointer Dereference). Because 5475 MHz does not correspond to a valid Wi-Fi channel, the cfg80211_next_nan_dw_notif function receives an invalid channel lookup result (NULL), and subsequently dereferences it without a NULL check. The fix is applied in two stable kernel commits: 1251bbdb8f5b2ea86ca9b4268a2e6aa34372ab33 and 333418872bfecf4843f1ded7a4151685dfcf07d5, correcting the frequency value to 5745 MHz (Kernel Git, Kernel Git).

Impact

Successful exploitation of this vulnerability could cause a kernel NULL pointer dereference, leading to a system crash (kernel panic) and denial of service on affected Linux systems. The impact is primarily limited to availability, as the crash would require a restart of the affected system. Because mac80211_hwsim is a simulation/testing driver typically used in development or virtualized environments rather than production wireless hardware, the real-world attack surface is relatively narrow (Feedly, EUVD).

Mitigation and workarounds

The vulnerability is fixed in Linux kernel stable releases patched at version 6.18.6 and 6.19-rc5, via commits 1251bbdb8f5b2ea86ca9b4268a2e6aa34372ab33 and 333418872bfecf4843f1ded7a4151685dfcf07d5. Red Hat has issued security advisories RHSA-2026:18134 and RHSA-2026:18587 addressing this issue for affected RHEL-based distributions. Users should update to a patched kernel version; as a workaround, unloading or blacklisting the mac80211_hwsim module on systems where it is not required will eliminate the attack surface (Red Hat Advisory, Red Hat Advisory, EUVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management