CVE-2026-98196
Received
Received - Intake
Use-After-Free in Linux Kernel brcmsmac WiFi Driver
Vulnerability report for CVE-2026-98196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmsmac: fix UAF in brcms_free_timer()
brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work. If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().
Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 5b435de0d786869c95d1962121af0d7df2542009 |
| Linux | Linux | 3.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |