CVE-2026-98196
Received Received - Intake

Use-After-Free in Linux Kernel brcmsmac WiFi Driver

Vulnerability report for CVE-2026-98196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: fix UAF in brcms_free_timer() brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous cancel_delayed_work() to cancel the timer's underlying delayed work. If the work callback (_brcms_timer) is already running, cancel_delayed_work() returns false without waiting, and brcms_free_timer() proceeds to kfree(t) while the callback still accesses t through container_of(). Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to guarantee that any in-flight callback has completed before the timer structure is freed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 5b435de0d786869c95d1962121af0d7df2542009
Linux Linux 3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free (UAF) vulnerability in the Linux kernel's wifi driver brcmsmac. The issue occurs in the brcms_free_timer() function which calls brcms_del_timer(). The function uses cancel_delayed_work() which may return without waiting if the timer's work callback is already running. This leads to a race condition where brcms_free_timer() frees the timer structure while the callback is still accessing it, causing a use-after-free error.

The fix involves adding cancel_delayed_work_sync() after brcms_del_timer() to ensure any ongoing callback completes before the timer structure is freed.

Detection Guidance

This vulnerability is specific to the Linux kernel's brcmsmac WiFi driver and involves a use-after-free (UAF) condition in the timer handling code. Detection requires checking if your system uses the affected driver version. Commands like 'lsmod | grep brcmsmac' can identify if the module is loaded. Kernel logs may show related errors if the issue has manifested.

Impact Analysis

This vulnerability could allow an attacker to cause a denial-of-service (system crash) or potentially execute arbitrary code with kernel privileges. Systems using the affected wifi driver (brcmsmac) may become unstable or compromised if the vulnerability is exploited.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this vulnerability. If immediate updating is not possible, consider disabling the brcmsmac driver if it is not required, using 'modprobe -r brcmsmac'. Monitor kernel logs for signs of exploitation or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart