CVE-2026-46166
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
28/05/2026
Last modified:
15/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: mac80211: use safe list iteration in radar detect work<br />
<br />
The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to<br />
be freed and removed from the list. Guard against this to avoid a<br />
slab-use-after-free error.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12 (including) | 6.12.88 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.30 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/120149fb3ebcf674832ca3cafd32bedcdb686dde
- https://git.kernel.org/stable/c/7577a4b8a10fab45a6ee2045ea038a5adadbb585
- https://git.kernel.org/stable/c/887ece6c23b49d02a6678e7a8d5ad213d75883ce
- https://git.kernel.org/stable/c/ac8eb3e18f41e2cc8492cc1d358bcb786c850270
- https://access.redhat.com/errata/RHSA-2026:27288
- https://access.redhat.com/errata/RHSA-2026:27708
- https://access.redhat.com/errata/RHSA-2026:27789
- https://access.redhat.com/errata/RHSA-2026:33215
- https://access.redhat.com/security/cve/CVE-2026-46166
- https://bugzilla.redhat.com/show_bug.cgi?id=2482645
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46166.json



