PT-2026-106525 · Linux · Linux

CVE-2026-98196

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmsmac: fix UAF in brcms free timer()
brcms free timer() calls brcms del timer() which uses the non-synchronous cancel delayed work() to cancel the timer's underlying delayed work. If the work callback ( brcms timer) is already running, cancel delayed work() returns false without waiting, and brcms free timer() proceeds to kfree(t) while the callback still accesses t through container of().
Add an explicit cancel delayed work sync() after brcms del timer() to guarantee that any in-flight callback has completed before the timer structure is freed.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98196

Produtos afetados

Linux