CVE-2026-98195
Received
Received - Intake
wifi: iwlegacy broadcast stations deallocation flaw
Vulnerability report for CVE-2026-98195, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlegacy: fix broadcast stations deallocation
On the error path of __il4965_up(), il_dealloc_bcast_stations() clears
only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the
same broadcast stations to be deallocated again by __il4965_down().
This can occur when RF_KILL is toggled during driver startup.
To fix clear the entire 'used' field, since we will not do any
other operations on the station.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | c2fd34469d1623111e3c3db65cde533f3bddc26e |
| Linux | Linux | 4.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |