Answer in brief
CVE-2026-98196 records a Unknown severity vulnerability in wifi: brcmsmac: fix UAF in brcms_free_timer(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5b435de0d786869c95d1962121af0d7df2542009 <10eeb0b29fd7f52487c9ae573e8d79c210a0095d || >=5b435de0d786869c95d1962121af0d7df2542009 <74acccc928851f69184271832d690607877122af || >=5b435de0d786869c95d1962121af0d7df2542009 <050d2486e8ed2c0a23b87249ccd23e8072721391 || >=5b435de0d786869c95d1962121af0d7df2542009 <856dabd5f2617efb23c043be9e1b22a9e6e97c41 || >=5b435de0d786869c95d1962121af0d7df2542009 <2a4841ff0b74b495cddd31ae324e922217fc2f13 || >=5b435de0d786869c95d1962121af0d7df2542009 <1edb3ddd261e973a4d577c0547e63bfa25a8170d || >=5b435de0d786869c95d1962121af0d7df2542009 <777cb6bba59e875b16a1d8897a483a5fecfcd5d2 || >=5b435de0d786869c95d1962121af0d7df2542009 <1eeca1d5e0920fbdad6449768fd2d4364e714180 | 10eeb0b29fd7f52487c9ae573e8d79c210a0095d, 74acccc928851f69184271832d690607877122af, 050d2486e8ed2c0a23b87249ccd23e8072721391, 856dabd5f2617efb23c043be9e1b22a9e6e97c41, 2a4841ff0b74b495cddd31ae324e922217fc2f13, 1edb3ddd261e973a4d577c0547e63bfa25a8170d, 777cb6bba59e875b16a1d8897a483a5fecfcd5d2, 1eeca1d5e0920fbdad6449768fd2d4364e714180 |
| Linux/Linuxgeneric | 3.2 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: fix UAF in brcms_free_timer() brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous cancel_delayed_work() to cancel the timer's underlying delayed work. If the work callback (_brcms_timer) is already running, cancel_delayed_work() returns false without waiting, and brcms_free_timer() proceeds to kfree(t) while the callback still accesses t through container_of(). Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to guarantee that any in-flight callback has completed before the timer structure is freed.
Quoted source text, attributed separately from HOL analysis.