๐Ÿ” CVE Alert

CVE-2026-68198

HIGH 8.8

wifi: ath6kl: fix use-after-free in aggr_reset_state()

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy(). If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy(). Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 23, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
bdcd81707973cf8aa9305337166f8ee842a050d4 < a1bac650b2d6b1baab1f3e78e2e007a6e2948dde bdcd81707973cf8aa9305337166f8ee842a050d4 < 2132a6db05846dd2318857d00e0c1291f9e41b29 bdcd81707973cf8aa9305337166f8ee842a050d4 < 17ff29cd8dbc977c97788a5f7c011ec807b58242 bdcd81707973cf8aa9305337166f8ee842a050d4 < 64af6534a085f49d6ed33338a19ab9cf0d0523c9 bdcd81707973cf8aa9305337166f8ee842a050d4 < b5d618fd61b9069b4c0a6b487022dd3117ad5acc bdcd81707973cf8aa9305337166f8ee842a050d4 < 18965470d41e69d3fc10eb62afae29d10f4cdfd1 bdcd81707973cf8aa9305337166f8ee842a050d4 < a3313111b5d9046af60b370c93eec105b27380c1 bdcd81707973cf8aa9305337166f8ee842a050d4 < ba7debb4dd6427386862220e8335a53a4bfc235d
Linux / Linux
3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a1bac650b2d6b1baab1f3e78e2e007a6e2948dde git.kernel.org: https://git.kernel.org/stable/c/2132a6db05846dd2318857d00e0c1291f9e41b29 git.kernel.org: https://git.kernel.org/stable/c/17ff29cd8dbc977c97788a5f7c011ec807b58242 git.kernel.org: https://git.kernel.org/stable/c/64af6534a085f49d6ed33338a19ab9cf0d0523c9 git.kernel.org: https://git.kernel.org/stable/c/b5d618fd61b9069b4c0a6b487022dd3117ad5acc git.kernel.org: https://git.kernel.org/stable/c/18965470d41e69d3fc10eb62afae29d10f4cdfd1 git.kernel.org: https://git.kernel.org/stable/c/a3313111b5d9046af60b370c93eec105b27380c1 git.kernel.org: https://git.kernel.org/stable/c/ba7debb4dd6427386862220e8335a53a4bfc235d