PT-2026-98540 · Linux · Linux Kernel

CVE-2026-97600

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the ieee802154 driver for the cc2520 device. The FIFOP interrupt handler queues cc2520 fifop irqwork, but during the removal process, the cc2520 remove() function only flushes the work. Because the devm-managed FIFOP IRQ remains active until after the removal function returns, it can re-queue the work after the flush, leading to execution after the private data has been released.
Recommendations Disable the work using the disable work sync() function instead of flushing it to prevent the handler from queuing work once removal begins. Ensure the buffer mutex is destroyed last, as it is required by the worker and the stop callback invoked through ieee802154 unregister hw().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97600

Affected Products

Linux Kernel