{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98192","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.323Z","datePublished":"2026-10-06T08:44:32.912Z","dateUpdated":"2026-10-06T08:44:32.912Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-06T08:44:32.912Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown\n\nwcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),\nwhich only dequeues the timer and does not wait for a callback that is\nalready executing; the preceding free_irq() calls synchronize the\ninterrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can\ntherefore be running past the teardown and use the wcn freed along\nwith the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock,\nreads wcn->tx_ack_skb and passes wcn->hw to\nieee80211_tx_status_irqsafe().\n\nFix this by using timer_shutdown_sync(), which waits for a running\ncallback and also prevents the timer from being rearmed again. The\ntimer is set up again by wcn36xx_dxe_init() on the next start, so the\nstart/stop cycle is unaffected.\n\nThis issue was found by an in-house static analysis tool."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/wcn36xx/dxe.c"],"versions":[{"version":"fdf21cc3714939dd4327f3d664fe5863d15ccb31","lessThan":"3edabc965bcce49cbb2ec1c2b91f8a555a8ec8bd","status":"affected","versionType":"git"},{"version":"fdf21cc3714939dd4327f3d664fe5863d15ccb31","lessThan":"2bddc5d088cf430ecd913020472f1def32a36a3d","status":"affected","versionType":"git"},{"version":"fdf21cc3714939dd4327f3d664fe5863d15ccb31","lessThan":"c0df0878e9110909cf0bec6080d72d36401a0c89","status":"affected","versionType":"git"},{"version":"fdf21cc3714939dd4327f3d664fe5863d15ccb31","lessThan":"d9be5e75530772fc31637070d51e5717d6aeaa2a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/ath/wcn36xx/dxe.c"],"versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3edabc965bcce49cbb2ec1c2b91f8a555a8ec8bd"},{"url":"https://git.kernel.org/stable/c/2bddc5d088cf430ecd913020472f1def32a36a3d"},{"url":"https://git.kernel.org/stable/c/c0df0878e9110909cf0bec6080d72d36401a0c89"},{"url":"https://git.kernel.org/stable/c/d9be5e75530772fc31637070d51e5717d6aeaa2a"}],"title":"wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown","x_generator":{"engine":"bippy-1.2.0"}}}}