PT-2026-98539 · Linux · Linux Kernel

CVE-2026-97599

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double-free issue exists in the ieee802154 module within the hwsim component. The hwsim update pib() function performs an unserialized read-swap-free operation on phy->pib. While the function assumes the RTNL (Routing Netlink) is held, the mac802154 scan worker can change channels via drv set channel() without holding the RTNL. This creates a race condition where two concurrent updates can read the same pib old pointer and both attempt to free it using kfree rcu(), leading to a double-free of the object. This may manifest as a KASAN invalid-free in rcu free sheaf() when using SLUB percpu sheaves.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97599

Affected Products

Linux Kernel