Expired pointer dereference in Linux kernel - CVE-2026-97492

 

Expired pointer dereference in Linux kernel - CVE-2026-97492

Published: September 24, 2026


Vulnerability identifier: #VU152001
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97492
CWE-ID: CWE-825
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to leave drivers with dangling pointers.

The vulnerability exists due to improper state cleanup in the mac80211 ieee80211_reconfig NAN reconfiguration failure handling when handling a failed NAN reconfiguration while other interfaces are present. A local user can trigger NAN reconfiguration processing that fails to leave drivers with dangling pointers.

The stale pointers can reference station and link objects.


Affected software

Linux kernel

How to mitigate CVE-2026-97492

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins