CVE-2026-23420
Low
No strong exploitation signal.
CVSS base
5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.1%
0.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-667
Published 2026-04-03 · modified 2026-07-24
CVSS breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | L | Local |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2026-04-03 — Published (NVD)
- 2026-07-24 — Last modified (NVD)
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Fix a locking bug Make sure that wl->mutex is locked before it is unlocked. This has been detected by the Clang thread-safety analyzer.
Affected
References
- https://git.kernel.org/stable/c/1a1c28a08d74716f3f8e3a21c86b30d0ff13521a
- https://git.kernel.org/stable/c/4ae8faf31b24c78653f4433298ee52813a56967a
- https://git.kernel.org/stable/c/5feeea59ed142e15c3284d0b1a364c6786bf3487
- https://git.kernel.org/stable/c/72c6df8f284b3a49812ce2ac136727ace70acc7c
- https://git.kernel.org/stable/c/7ab511003c5ae3bf5364d7699a2e3ab1db513680
- https://git.kernel.org/stable/c/aca4c9e4901b01b8b985993dc7df80bd1d1338bd
- https://git.kernel.org/stable/c/fc404390a386404cf9822d4091ccae1f61efcbcd
- https://git.kernel.org/stable/c/fcef983ad88832f3aa83491a174c345de57afbbd