Linux Kernel Vulnerability in BCMA Wireless Driver
CVE-2026-98052

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98052?

A vulnerability in the BCMA wireless driver of the Linux kernel can lead to premature buffer consumption during data transmission. The issue arises when the 'last' field of the transmission control block is not cleared properly for non-final data fragments. This oversight permits the reuse of descriptor slots that contain stale values, potentially freeing memory associated with ongoing SKB fragments. To mitigate this risk, the implementation should ensure 'last' is consistently reset to a known state before being conditionally set, thus maintaining data integrity and preventing premature data loss.

Affected Version(s)

Linux 490cb412007de593e07c1d3e2b1ec4233886707c < 1e213ba7cb3b9dd97ac2e0a1054e6d0d1d91f5bc

Linux 490cb412007de593e07c1d3e2b1ec4233886707c < 9b26b54861ce05307d39a54ddedddf8747419614

Linux 490cb412007de593e07c1d3e2b1ec4233886707c < 47a5cecca925ceb175d5adf712e667acf78f475f

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.