CVE-2026-23246 | Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1 wifi ieee80211_ml_reconfiguration link_id out-of-bounds (EUVD-2026-12809 / Nessus ID 302910)
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1. This affects the function ieee80211_ml_reconfiguration of the component wifi. Such manipulation of the argument link_id leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-23246. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.