CVE-2026-98196

Source
https://cve.org/CVERecord?id=CVE-2026-98196
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98196.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98196
Downstream
Published
2026-10-06T08:44:35Z
Modified
2026-10-07T02:47:32Z
Summary
wifi: brcmsmac: fix UAF in brcms_free_timer()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmsmac: fix UAF in brcms_free_timer()

brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous cancel_delayed_work() to cancel the timer's underlying delayed work. If the work callback (_brcms_timer) is already running, cancel_delayed_work() returns false without waiting, and brcms_free_timer() proceeds to kfree(t) while the callback still accesses t through container_of().

Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to guarantee that any in-flight callback has completed before the timer structure is freed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98196.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b435de0d786869c95d1962121af0d7df2542009
Fixed
10eeb0b29fd7f52487c9ae573e8d79c210a0095d
Fixed
74acccc928851f69184271832d690607877122af
Fixed
050d2486e8ed2c0a23b87249ccd23e8072721391
Fixed
856dabd5f2617efb23c043be9e1b22a9e6e97c41
Fixed
2a4841ff0b74b495cddd31ae324e922217fc2f13
Fixed
1edb3ddd261e973a4d577c0547e63bfa25a8170d
Fixed
777cb6bba59e875b16a1d8897a483a5fecfcd5d2
Fixed
1eeca1d5e0920fbdad6449768fd2d4364e714180

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98196.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98196.json"