PT-2026-106525 · Linux · Linux

CVE-2026-98196

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmsmac: fix UAF in brcms free timer()
brcms free timer() calls brcms del timer() which uses the non-synchronous cancel delayed work() to cancel the timer's underlying delayed work. If the work callback ( brcms timer) is already running, cancel delayed work() returns false without waiting, and brcms free timer() proceeds to kfree(t) while the callback still accesses t through container of().
Add an explicit cancel delayed work sync() after brcms del timer() to guarantee that any in-flight callback has completed before the timer structure is freed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98196

Affected Products

Linux