CVE-2026-97541

medium

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: don't store usb_device_id usb_device_id is not guaranteed to live longer than probe due to presence of dynamic ID. All information apart from driver_data can be easily retrieved from usb_device, so just store driver_data.

References

https://git.kernel.org/stable/c/c34aa59950597e3360e9cef9d08cdf4edb30ad4d

https://git.kernel.org/stable/c/9d5e396578097d02e859798207db41ed4b831f50

https://git.kernel.org/stable/c/8e70a6785bd02cf9ef7fd21ebccf46a8ba23014e

https://git.kernel.org/stable/c/14d2ac442d660e112efc0ce87ad10085013ed2b1

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-25

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.002