๐Ÿ” CVE Alert

CVE-2026-97600

UNKNOWN 0.0

ieee802154: cc2520: fix FIFOP work use-after-free

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ieee802154: cc2520: fix FIFOP work use-after-free The FIFOP interrupt handler queues cc2520_fifop_irqwork. On removal, cc2520_remove() only flushes the work. The devm-managed FIFOP IRQ remains active until after ->remove() returns and can queue the work again after that flush, allowing it to run after the private data is released. Disable the work with disable_work_sync() instead of flushing it, so the handler can no longer queue it once removal begins. Destroy the buffer mutex last, since the worker and the stop callback invoked through ieee802154_unregister_hw() both take it. Found by an in-house static analysis tool.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0da6bc8cc3417a5e452efb886ff2c61e72b743d6 < 56a9919d8494fb118eebf167bef0622528fbf2e7 0da6bc8cc3417a5e452efb886ff2c61e72b743d6 < c68fd52c73b676aee67020011e98fea125a978f4 0da6bc8cc3417a5e452efb886ff2c61e72b743d6 < 890a80d516a1447db5c21bf92841a82914ea897d 0da6bc8cc3417a5e452efb886ff2c61e72b743d6 < ff5891b266a7fc6a062710836be84f1cc19338b5
Linux / Linux
3.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/56a9919d8494fb118eebf167bef0622528fbf2e7 git.kernel.org: https://git.kernel.org/stable/c/c68fd52c73b676aee67020011e98fea125a978f4 git.kernel.org: https://git.kernel.org/stable/c/890a80d516a1447db5c21bf92841a82914ea897d git.kernel.org: https://git.kernel.org/stable/c/ff5891b266a7fc6a062710836be84f1cc19338b5