Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98160— staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: staging: rtl8723bs:修复 rtw_sdio_if1_init() 中 HalData 的不匹配释放问题 padapter->HalData 是通过 vzalloc() 分配的,但在 rtw_sdio_if1_init() 的错误处理路径中却错误地使用 kfree() 进行释放。使用 kfree() 释放由 vmalloc() 分配的缓冲区可能导致内存损坏。 应使用 rtw_hal_data_deinit() 正确配对释放操作,并通过 vfree() 释放

AI Predicted 5.5 Difficulty: Hard EPSS 0.17% · P5

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b< ff6d1ba247b5c62bdb678f1069abc86ad88a1402 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< d6158333d630a1b21d8914feaf77a6f5deb185d9 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 6c017ab2b0e1b60b5be94636c94720347213d78b affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 4520d673d49dabfd42c008a33889251025f7d6d5 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 423574feaed192063ef0cd0813fb85425f39e539 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 737c928ff5092d7e55128a232c231248fc993777 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 911190f0b9511c3c81f2f2484414c1ae26f636b3 affected
554c0a3abf216c991c5ebddcdb2c08689ecd290b< 264676418b726baca7be49171e306b6aa05cceb0 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98160

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can lead to memory corruption. Use rtw_hal_data_deinit() to pair the free correctly and free HalData with vfree(). The bug was first flagged by an experimental static analysis tool we are developing for kernel memory-management bugs. Manual inspection confirms that the issue is still present in current mainline. An x86_64 allyesconfig build showed no new warnings. As we do not have suitable RTL8723BS SDIO hardware to test with, no runtime testing was able to be performed.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b ~ ff6d1ba247b5c62bdb678f1069abc86ad88a1402 -
Linux Linux 4.12 -

II. Public POCs for CVE-2026-98160

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98160

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98160 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98122 7.8 HIGH vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98160

No comments yet


Leave a comment