CVE-2026-98194
Received
Received - Intake
Use-After-Free in Linux Kernel Libertas TF Driver
Vulnerability report for CVE-2026-98194, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas_tf: fix UAF in lbtf_free_adapter()
lbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command
buffers before calling timer_delete_sync() to wait for the command
timer callback. If the timer callback (command_timer_fn) is already
running when lbtf_free_cmd_buffer() frees the command array, the
callback dereferences priv->cur_cmd->cmdbuf which points to freed
memory.
Swap the order so that timer_delete_sync() runs first, ensuring any
in-flight callback has completed before the command buffers are freed.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 06b16ae5319251c26377afcb401e46056d5673f4 |
| Linux | Linux | 2.6.28 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |