PT-2026-106525 · Linux · Linux
CVE-2026-98196
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmsmac: fix UAF in brcms free timer()
brcms free timer() calls brcms del timer() which uses the non-synchronous
cancel delayed work() to cancel the timer's underlying delayed work. If
the work callback ( brcms timer) is already running, cancel delayed work()
returns false without waiting, and brcms free timer() proceeds to kfree(t)
while the callback still accesses t through container of().
Add an explicit cancel delayed work sync() after brcms del timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux