CVE-2026-98195
Received Received - Intake

wifi: iwlegacy broadcast stations deallocation flaw

Vulnerability report for CVE-2026-98195, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: fix broadcast stations deallocation On the error path of __il4965_up(), il_dealloc_bcast_stations() clears only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the same broadcast stations to be deallocated again by __il4965_down(). This can occur when RF_KILL is toggled during driver startup. To fix clear the entire 'used' field, since we will not do any other operations on the station.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux c2fd34469d1623111e3c3db65cde533f3bddc26e
Linux Linux 4.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's wifi driver (iwlegacy). It occurs when the driver fails to properly clear broadcast station allocations during an error path in the startup process. Specifically, when RF_KILL is toggled during driver startup, the driver may attempt to deallocate the same broadcast stations twice, leading to potential system instability or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's iwlegacy WiFi driver and may not have direct detection commands. Monitor kernel logs for errors related to the iwlegacy driver or WiFi broadcast station deallocation issues during driver startup or RF_KILL toggling.

Impact Analysis

This vulnerability could cause system instability or crashes if RF_KILL is toggled during the driver's startup. It may lead to WiFi connectivity issues or require a system reboot to recover normal operation.

Mitigation Strategies

Update your Linux kernel to the latest version that includes the fix for this vulnerability. If you are using a distribution with a vulnerable kernel, apply the patch provided by your distribution vendor immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98195. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart