In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list iteration in radar detect work The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to be freed and removed from the list. Guard against this to avoid a slab-use-after-free error.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026052826-CVE-2026-46166-77a1@gregkh/T