CVE-2026-98195

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlegacy: fix broadcast stations deallocation

On the error path of __il4965_up(), il_dealloc_bcast_stations() clears only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the same broadcast stations to be deallocated again by __il4965_down().

This can occur when RF_KILL is toggled during driver startup.

To fix clear the entire 'used' field, since we will not do any other operations on the station.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < 275d474a4b4bd4e73b18b1452f12e78806a8843aaffected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < 526fdd45548e22eee50ee1062abd88269d9f32e0affected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < c9a116d691364cd7f59d8329b395adcaf826d5c6affected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < 85d847ff71fe736cbc15ada321256818e630e205affected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < 1d84c2a3de449aceb94ed79eaefecdf1bedb6468affected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < 55d34422c0d91436983028fd3c1546a1c2bee55faffected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < a9176fe666af1730cab92350f9c8cf67ebf14439affected
LinuxLinuxc2fd34469d1623111e3c3db65cde533f3bddc26e < b5526b780f8b297a76030410b96ba29153afb98faffected
LinuxLinux4.7affected
LinuxLinux0 < 4.7unaffected
LinuxLinux5.10.271 <= 5.10.*unaffected
LinuxLinux5.15.222 <= 5.15.*unaffected
LinuxLinux6.1.189 <= 6.1.*unaffected
LinuxLinux6.6.158 <= 6.6.*unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References