CVE-2026-46125
Linux kernel wifi mac80211 use-after-free during MLO prep; debugfs risk.
Is CVE-2026-46125 being exploited?
Not confirmed. CVE-2026-46125 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.30% probability of exploitation in the next 30 days.
How severe is CVE-2026-46125?
CVE-2026-46125 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-46125?
Yes. A fix has been recorded for CVE-2026-46125. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-46125 affect?
CVE-2026-46125 affects Linux kernel - wifi/mac80211. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-46125?
Update to patched kernel
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local memory corruption could crash kernel; may be exploitable if debugfs is enabled.
Patch when possible
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < 18fed0a209500bfea5c4c08609ec93855e4e500b
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < fe75fa1ac9a92990f7fc3d34b17808fd933071b2
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < afcbaed89cdc1a001b43270cbf5394bb4804270a
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < 9e28654f79f443bca9b29ff3ae7cf18abfba58a0
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < 1c2b72ea89882aeb948340498391e69c58d466f1
- affected>= 81151ce462e533551f3284bfdb8e0f461c9220e6 and < 283fc9e44ff5b5ac967439b4951b80bd4299f4e4
- affected6.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.