« Volver al listado

CVE-2026-97600

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: cc2520: fix FIFOP work use-after-free

The FIFOP interrupt handler queues cc2520_fifop_irqwork. On removal, cc2520_remove() only flushes the work. The devm-managed FIFOP IRQ remains active until after ->remove() returns and can queue the work again after that flush, allowing it to run after the private data is released.

Disable the work with disable_work_sync() instead of flushing it, so the handler can no longer queue it once removal begins. Destroy the buffer mutex last, since the worker and the stop callback invoked through ieee802154_unregister_hw() both take it.

Leer descripción completaMostrar menos

Found by an in-house static analysis tool.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97600",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0da6bc8cc3417a5e452efb886ff2c61e72b743d6",
              "lessThan": "56a9919d8494fb118eebf167bef0622528fbf2e7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0da6bc8cc3417a5e452efb886ff2c61e72b743d6",
              "lessThan": "c68fd52c73b676aee67020011e98fea125a978f4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0da6bc8cc3417a5e452efb886ff2c61e72b743d6",
              "lessThan": "890a80d516a1447db5c21bf92841a82914ea897d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0da6bc8cc3417a5e452efb886ff2c61e72b743d6",
              "lessThan": "ff5891b266a7fc6a062710836be84f1cc19338b5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/cc2520.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/cc2520.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:11.353",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/56a9919d8494fb118eebf167bef0622528fbf2e7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/890a80d516a1447db5c21bf92841a82914ea897d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c68fd52c73b676aee67020011e98fea125a978f4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff5891b266a7fc6a062710836be84f1cc19338b5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: cc2520: fix FIFOP work use-after-free\n\nThe FIFOP interrupt handler queues cc2520_fifop_irqwork.  On removal,\ncc2520_remove() only flushes the work.  The devm-managed FIFOP IRQ\nremains active until after ->remove() returns and can queue the work\nagain after that flush, allowing it to run after the private data is\nreleased.\n\nDisable the work with disable_work_sync() instead of flushing it, so\nthe handler can no longer queue it once removal begins.  Destroy the\nbuffer mutex last, since the worker and the stop callback invoked\nthrough ieee802154_unregister_hw() both take it.\n\nFound by an in-house static analysis tool."
    }
  ],
  "lastModified": "2026-09-25T11:17:11.353",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}