0.0
NA
CVE-2026-98160
staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
Description

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can lead to memory corruption. Use rtw_hal_data_deinit() to pair the free correctly and free HalData with vfree(). The bug was first flagged by an experimental static analysis tool we are developing for kernel memory-management bugs. Manual inspection confirms that the issue is still present in current mainline. An x86_64 allyesconfig build showed no new warnings. As we do not have suitable RTL8723BS SDIO hardware to test with, no runtime testing was able to be performed.

INFO

Published Date :

Sept. 25, 2026, 2:17 p.m.

Last Modified :

Sept. 30, 2026, 2:10 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-98160 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Correctly free memory allocated with vzalloc() using vfree() to prevent corruption.
  • Use rtw_hal_data_deinit() to pair the free correctly.
  • Free HalData with vfree() in the error path.
  • Apply the vendor-provided patch to fix memory management.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-98160 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-98160 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-98160 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-98160 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 25, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can lead to memory corruption. Use rtw_hal_data_deinit() to pair the free correctly and free HalData with vfree(). The bug was first flagged by an experimental static analysis tool we are developing for kernel memory-management bugs. Manual inspection confirms that the issue is still present in current mainline. An x86_64 allyesconfig build showed no new warnings. As we do not have suitable RTL8723BS SDIO hardware to test with, no runtime testing was able to be performed.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/98xxx/CVE-2026-98160.json">CVE-2026-98160</a>
    Added Reference https://git.kernel.org/stable/c/264676418b726baca7be49171e306b6aa05cceb0
    Added Reference https://git.kernel.org/stable/c/423574feaed192063ef0cd0813fb85425f39e539
    Added Reference https://git.kernel.org/stable/c/4520d673d49dabfd42c008a33889251025f7d6d5
    Added Reference https://git.kernel.org/stable/c/6c017ab2b0e1b60b5be94636c94720347213d78b
    Added Reference https://git.kernel.org/stable/c/737c928ff5092d7e55128a232c231248fc993777
    Added Reference https://git.kernel.org/stable/c/911190f0b9511c3c81f2f2484414c1ae26f636b3
    Added Reference https://git.kernel.org/stable/c/d6158333d630a1b21d8914feaf77a6f5deb185d9
    Added Reference https://git.kernel.org/stable/c/ff6d1ba247b5c62bdb678f1069abc86ad88a1402
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.