Mismatched Memory Management Routines in Linux kernel - CVE-2026-98160
Published: September 28, 2026
Vulnerability identifier: #VU152268
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98160
CWE-ID: CWE-762
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to mismatched memory management routines in rtw_sdio_if1_init() when handling an initialization failure after allocating HalData. A local user can trigger the initialization error path to cause memory corruption.
Affected software
Linux kernel
How to mitigate CVE-2026-98160
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/264676418b726baca7be49171e306b6aa05cceb0
- https://git.kernel.org/stable/c/423574feaed192063ef0cd0813fb85425f39e539
- https://git.kernel.org/stable/c/4520d673d49dabfd42c008a33889251025f7d6d5
- https://git.kernel.org/stable/c/6c017ab2b0e1b60b5be94636c94720347213d78b
- https://git.kernel.org/stable/c/737c928ff5092d7e55128a232c231248fc993777
- https://git.kernel.org/stable/c/911190f0b9511c3c81f2f2484414c1ae26f636b3
- https://git.kernel.org/stable/c/d6158333d630a1b21d8914feaf77a6f5deb185d9
- https://git.kernel.org/stable/c/ff6d1ba247b5c62bdb678f1069abc86ad88a1402