← All Advisories

CVE-2026-97599

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97599

Key Details

CVECVE-2026-97599
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: hwsim: serialize pib updates to fix double-free

hwsim_update_pib() does an unserialized read-swap-free of phy->pib:

pib_old = rtnl_dereference(phy->pib);

...

rcu_assign_pointer(phy->pib, pib);

kfree_rcu(pib_old, rcu);

It assumes the RTNL is held, but ->set_channel is not always called

under it: the mac802154 scan worker changes channels via

drv_set_channel() without the RTNL. Such an update can race an

RTNL-held one on the same phy; both read the same pib_old and both

kfree_rcu() it, double-freeing the object. With SLUB percpu sheaves

batching kfree_rcu(), this surfaces as a KASAN invalid-free in

rcu_free_sheaf().

struct hwsim_phy has no lock for pib. Add one and make the swap atomic

with rcu_replace_pointer() under it, dropping the misleading

rtnl_dereference(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97599
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97599