{"id":"CVE-2026-98192","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown\n\nwcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),\nwhich only dequeues the time…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown\n\nwcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),\nwhich only dequeues the time…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= fdf21cc3714939dd4327f3d664fe5863d15ccb31 < 3edabc965bcce49cbb2ec1c2b91f8a555a8ec8bd","Linux >= fdf21cc3714939dd4327f3d664fe5863d15ccb31 < 2bddc5d088cf430ecd913020472f1def32a36a3d","Linux >= fdf21cc3714939dd4327f3d664fe5863d15ccb31 < c0df0878e9110909cf0bec6080d72d36401a0c89","Linux >= fdf21cc3714939dd4327f3d664fe5863d15ccb31 < d9be5e75530772fc31637070d51e5717d6aeaa2a","Linux 5.10"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:04.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98192","references":[{"url":"https://git.kernel.org/stable/c/2bddc5d088cf430ecd913020472f1def32a36a3d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3edabc965bcce49cbb2ec1c2b91f8a555a8ec8bd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0df0878e9110909cf0bec6080d72d36401a0c89","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9be5e75530772fc31637070d51e5717d6aeaa2a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.448Z","slug":"CVE-2026-98192","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown\n\nwcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),\nwhich only dequeues the timer and does not wait for a callback that is\nalready executing; the preceding free_irq() calls synchronize the\ninterrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can\ntherefore be running past the teardown and use the wcn freed along\nwith the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock,\nreads wcn->tx_ack_skb and passes wcn->hw to\nieee80211_tx_status_irqsafe().\n\nFix this by using timer_shutdown_sync(), which waits for a running\ncallback and also prevents the timer from being rearmed again. The\ntimer is set up again by wcn36xx_dxe_init() on the next start, so the\nstart/stop cycle is unaffected.\n\nThis issue was found by an in-house static analysis tool.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}