{"id":"CVE-2026-98194","summary":"wifi: libertas_tf: fix UAF in lbtf_free_adapter()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas_tf: fix UAF in lbtf_free_adapter()\n\nlbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command\nbuffers before calling timer_delete_sync() to wait for the command\ntimer callback.  If the timer callback (command_timer_fn) is already\nrunning when lbtf_free_cmd_buffer() frees the command array, the\ncallback dereferences priv-\u003ecur_cmd-\u003ecmdbuf which points to freed\nmemory.\n\nSwap the order so that timer_delete_sync() runs first, ensuring any\nin-flight callback has completed before the command buffers are freed.","modified":"2026-10-08T02:52:52.673663628Z","published":"2026-10-06T08:44:34.253Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98194.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/04c837d413dc11a91e0275b08b9e35a6c111175e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2b99bfc5a127ce8cd6a887d82815fc2e712f365b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3fb3663260ec396f86b733aab9f81fac6669d2fa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/41b1a4d545ec348b7d5324b6d4f4c6a3e0326d46"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b4745d6063758c681d33affca9733bbd356b6ea1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bbb9a0ab96d44a64529aafc7a16de460a1712f6a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e82536aad653e27c8ca7a8e0f6f816bc3f853ec3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f6c3fa0d17ca0c9e6033bb45f52e33b27a9a40e6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98194.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98194"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"06b16ae5319251c26377afcb401e46056d5673f4"},{"fixed":"3fb3663260ec396f86b733aab9f81fac6669d2fa"},{"fixed":"f6c3fa0d17ca0c9e6033bb45f52e33b27a9a40e6"},{"fixed":"b4745d6063758c681d33affca9733bbd356b6ea1"},{"fixed":"41b1a4d545ec348b7d5324b6d4f4c6a3e0326d46"},{"fixed":"2b99bfc5a127ce8cd6a887d82815fc2e712f365b"},{"fixed":"e82536aad653e27c8ca7a8e0f6f816bc3f853ec3"},{"fixed":"04c837d413dc11a91e0275b08b9e35a6c111175e"},{"fixed":"bbb9a0ab96d44a64529aafc7a16de460a1712f6a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98194.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.28"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98194.json"}}],"schema_version":"1.9.0"}