CVE-2026-23315
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23315 is an out-of-bounds memory access vulnerability in the Linux kernel's mt76 WiFi driver, specifically within the mt76_connac2_mac_write_txwi_80211() function. The flaw arises from insufficient frame length validation before accessing management frame fields, including mgmt->u.action.u.addba_req.capab. It affects Linux kernel versions from 5.10 through multiple stable branches, with fixed versions including 6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7, and 7.0-rc3. It was published on March 25, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, Feedly).

Technical details

The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read), and maps to CAPEC-540 (Overread Buffers). The root cause is the absence of a frame length check in mt76_connac2_mac_write_txwi_80211() before dereferencing management frame fields; a malformed or undersized WiFi management frame can cause the driver to read or write beyond the allocated buffer boundary. Exploitation requires local access with low privileges — an attacker with a local account on a system using mt76-based WiFi hardware could trigger the flaw by crafting or injecting malformed 802.11 management frames. No public proof-of-concept code has been identified (Red Hat CVE, Feedly).

Impact

Successful exploitation can result in kernel memory corruption, potentially leading to a denial of service (system crash or hang) or local privilege escalation. Confidentiality and availability are both rated High in the CVSS scoring, reflecting the risk of sensitive kernel memory exposure and system instability. The vulnerability is scoped to the local system and does not directly enable remote code execution or lateral movement, but privilege escalation could allow an attacker to gain full control of the affected host (Red Hat CVE, Feedly).

Mitigation and workarounds

Apply kernel updates containing the fix for this vulnerability. Patched versions are available across multiple stable branches: Linux kernel 6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7, and 7.0-rc3 or later. Distribution-specific updates have been issued by Debian (DSA-6238-1, DSA-6243-1, DLA-4561-1) and SUSE (SUSE-SU-2026:2217-1, SUSE-SU-2026:2238-1). As a workaround where patching is not immediately possible, restrict local user access on systems using mt76-based WiFi hardware and monitor kernel logs for memory corruption or WiFi driver errors (Red Hat CVE, SUSE Advisory, Debian DSA-6238).

Community reactions

The vulnerability has been tracked by major Linux distribution vendors including Debian, SUSE, and Red Hat, all of which have issued security advisories and kernel updates. The Yocto Project security mailing list also flagged the issue for embedded Linux users. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vendor patch notifications (Debian DSA-6238, SUSE Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management