-

CVE-2026-97600

ieee802154: cc2520: fix FIFOP work use-after-free

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: cc2520: fix FIFOP work use-after-free

The FIFOP interrupt handler queues cc2520_fifop_irqwork.  On removal,
cc2520_remove() only flushes the work.  The devm-managed FIFOP IRQ
remains active until after ->remove() returns and can queue the work
again after that flush, allowing it to run after the private data is
released.

Disable the work with disable_work_sync() instead of flushing it, so
the handler can no longer queue it once removal begins.  Destroy the
buffer mutex last, since the worker and the stop callback invoked
through ieee802154_unregister_hw() both take it.

Found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0da6bc8cc3417a5e452efb886ff2c61e72b743d6
Version < 56a9919d8494fb118eebf167bef0622528fbf2e7
Status affected
Version 0da6bc8cc3417a5e452efb886ff2c61e72b743d6
Version < c68fd52c73b676aee67020011e98fea125a978f4
Status affected
Version 0da6bc8cc3417a5e452efb886ff2c61e72b743d6
Version < 890a80d516a1447db5c21bf92841a82914ea897d
Status affected
Version 0da6bc8cc3417a5e452efb886ff2c61e72b743d6
Version < ff5891b266a7fc6a062710836be84f1cc19338b5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.17
Status affected
Version 0
Version < 3.17
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/56a9919d8494fb118eebf167bef0622528fbf2e7
https://git.kernel.org/stable/c/c68fd52c73b676aee67020011e98fea125a978f4
https://git.kernel.org/stable/c/890a80d516a1447db5c21bf92841a82914ea897d
https://git.kernel.org/stable/c/ff5891b266a7fc6a062710836be84f1cc19338b5