---
id: CVE-2026-98196
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: brcmsmac: fix UAF in brcms_free_timer()

  brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
  cancel_delayed_work() to cancel the timer's und…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: brcmsmac: fix UAF in brcms_free_timer()

  brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
  cancel_delayed_work() to cancel the timer's und…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    10eeb0b29fd7f52487c9ae573e8d79c210a0095d
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    74acccc928851f69184271832d690607877122af
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    050d2486e8ed2c0a23b87249ccd23e8072721391
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    856dabd5f2617efb23c043be9e1b22a9e6e97c41
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    2a4841ff0b74b495cddd31ae324e922217fc2f13
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    1edb3ddd261e973a4d577c0547e63bfa25a8170d
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    777cb6bba59e875b16a1d8897a483a5fecfcd5d2
  - >-
    Linux >= 5b435de0d786869c95d1962121af0d7df2542009 <
    1eeca1d5e0920fbdad6449768fd2d4364e714180
  - Linux 3.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:05.113'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98196'
references:
  - url: 'https://git.kernel.org/stable/c/050d2486e8ed2c0a23b87249ccd23e8072721391'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/10eeb0b29fd7f52487c9ae573e8d79c210a0095d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1edb3ddd261e973a4d577c0547e63bfa25a8170d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1eeca1d5e0920fbdad6449768fd2d4364e714180'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2a4841ff0b74b495cddd31ae324e922217fc2f13'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/74acccc928851f69184271832d690607877122af'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/777cb6bba59e875b16a1d8897a483a5fecfcd5d2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/856dabd5f2617efb23c043be9e1b22a9e6e97c41'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.448Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmsmac: fix UAF in brcms_free_timer()

brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work.  If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().

Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
