CVE-2026-98195
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlegacy: fix broadcast stations deallocation
On the error path of __il4965_up(), il_dealloc_bcast_stations() clears only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the same broadcast stations to be deallocated again by __il4965_down().
This can occur when RF_KILL is toggled during driver startup.
To fix clear the entire 'used' field, since we will not do any other operations on the station.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1d84c2a3de449aceb94ed79eaefecdf1bedb6468
- https://git.kernel.org/stable/c/275d474a4b4bd4e73b18b1452f12e78806a8843a
- https://git.kernel.org/stable/c/526fdd45548e22eee50ee1062abd88269d9f32e0
- https://git.kernel.org/stable/c/55d34422c0d91436983028fd3c1546a1c2bee55f
- https://git.kernel.org/stable/c/85d847ff71fe736cbc15ada321256818e630e205
- https://git.kernel.org/stable/c/a9176fe666af1730cab92350f9c8cf67ebf14439
- https://git.kernel.org/stable/c/b5526b780f8b297a76030410b96ba29153afb98f
- https://git.kernel.org/stable/c/c9a116d691364cd7f59d8329b395adcaf826d5c6
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98195",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "275d474a4b4bd4e73b18b1452f12e78806a8843a",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "526fdd45548e22eee50ee1062abd88269d9f32e0",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "c9a116d691364cd7f59d8329b395adcaf826d5c6",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "85d847ff71fe736cbc15ada321256818e630e205",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "1d84c2a3de449aceb94ed79eaefecdf1bedb6468",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "55d34422c0d91436983028fd3c1546a1c2bee55f",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "a9176fe666af1730cab92350f9c8cf67ebf14439",
"versionType": "git"
},
{
"status": "affected",
"version": "c2fd34469d1623111e3c3db65cde533f3bddc26e",
"lessThan": "b5526b780f8b297a76030410b96ba29153afb98f",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/intel/iwlegacy/common.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/intel/iwlegacy/common.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:04.953",
"references": [
{
"url": "https://git.kernel.org/stable/c/1d84c2a3de449aceb94ed79eaefecdf1bedb6468",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/275d474a4b4bd4e73b18b1452f12e78806a8843a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/526fdd45548e22eee50ee1062abd88269d9f32e0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/55d34422c0d91436983028fd3c1546a1c2bee55f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/85d847ff71fe736cbc15ada321256818e630e205",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9176fe666af1730cab92350f9c8cf67ebf14439",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b5526b780f8b297a76030410b96ba29153afb98f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c9a116d691364cd7f59d8329b395adcaf826d5c6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlegacy: fix broadcast stations deallocation\n\nOn the error path of __il4965_up(), il_dealloc_bcast_stations() clears\nonly IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the\nsame broadcast stations to be deallocated again by __il4965_down().\n\nThis can occur when RF_KILL is toggled during driver startup.\n\nTo fix clear the entire 'used' field, since we will not do any\nother operations on the station."
}
],
"lastModified": "2026-10-06T09:18:04.953",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}