PT-2026-98540 · Linux · Linux Kernel
CVE-2026-97600
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
ieee802154 driver for the cc2520 device. The FIFOP interrupt handler queues cc2520 fifop irqwork, but during the removal process, the cc2520 remove() function only flushes the work. Because the devm-managed FIFOP IRQ remains active until after the removal function returns, it can re-queue the work after the flush, leading to execution after the private data has been released.Recommendations
Disable the work using the
disable work sync() function instead of flushing it to prevent the handler from queuing work once removal begins.
Ensure the buffer mutex is destroyed last, as it is required by the worker and the stop callback invoked through ieee802154 unregister hw(). Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel