Answer in brief
CVE-2026-98195 records a Unknown severity vulnerability in wifi: iwlegacy: fix broadcast stations deallocation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c2fd34469d1623111e3c3db65cde533f3bddc26e <275d474a4b4bd4e73b18b1452f12e78806a8843a || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <526fdd45548e22eee50ee1062abd88269d9f32e0 || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <c9a116d691364cd7f59d8329b395adcaf826d5c6 || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <85d847ff71fe736cbc15ada321256818e630e205 || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <1d84c2a3de449aceb94ed79eaefecdf1bedb6468 || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <55d34422c0d91436983028fd3c1546a1c2bee55f || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <a9176fe666af1730cab92350f9c8cf67ebf14439 || >=c2fd34469d1623111e3c3db65cde533f3bddc26e <b5526b780f8b297a76030410b96ba29153afb98f | 275d474a4b4bd4e73b18b1452f12e78806a8843a, 526fdd45548e22eee50ee1062abd88269d9f32e0, c9a116d691364cd7f59d8329b395adcaf826d5c6, 85d847ff71fe736cbc15ada321256818e630e205, 1d84c2a3de449aceb94ed79eaefecdf1bedb6468, 55d34422c0d91436983028fd3c1546a1c2bee55f, a9176fe666af1730cab92350f9c8cf67ebf14439, b5526b780f8b297a76030410b96ba29153afb98f |
| Linux/Linuxgeneric | 4.7 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: fix broadcast stations deallocation On the error path of __il4965_up(), il_dealloc_bcast_stations() clears only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the same broadcast stations to be deallocated again by __il4965_down(). This can occur when RF_KILL is toggled during driver startup. To fix clear the entire 'used' field, since we will not do any other operations on the station.
Quoted source text, attributed separately from HOL analysis.