← Back to CVE intelligence
CVE intelligence

CVE-2026-63822

Vulnerability intelligence

Published Jul 19, 2026Sources checked Oct 9, 2026
N/ACVSS not listedScore unavailable
What this means

Review the available evidence

CVE-2026-63822. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-63822?

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix warning when unbinding

If there is an error during some initialization related to firmware, the buffers dp->tx_ring[i].tx_status are released. However this is released again when the device is unbinded (ath11k_pci), and we get: WARNING: CPU: 0 PID: 6231 at mm/slub.c:4368 free_large_kmalloc+0x57/0x90 Call Trace: free_large_kmalloc ath11k_dp_free ath11k_core_deinit ath11k_pci_remove ...

The issue is always reproducible from a VM because the MSI addressing initialization is failing.

In order to fix the issue, just set the buffers to NULL after releasing in order to avoid the double free.

Source: NVD