{"id":"AZL-106170","summary":"CVE-2026-98195 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlegacy: fix broadcast stations deallocation\n\nOn the error path of __il4965_up(), il_dealloc_bcast_stations() clears\nonly IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the\nsame broadcast stations to be deallocated again by __il4965_down().\n\nThis can occur when RF_KILL is toggled during driver startup.\n\nTo fix clear the entire 'used' field, since we will not do any\nother operations on the station.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:04Z","upstream":["CVE-2026-98195"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98195"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106170.json"}}],"schema_version":"1.9.0"}