PT-2026-106656 · Linux · Linux

CVE-2026-98327

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: mesh: reset the CSA state when leaving
ifmsh->csa is allocated in ieee80211 mesh csa beacon() and only freed in ieee80211 mesh finish csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it.
Additionally, ifmsh->csa role and ifmsh->chsw ttl have their state leak in this case, so things can get mixed up in addition to the memory leak.
Refactor the reset and call it in ieee80211 stop mesh() to fix it all.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98327

Affected Products

Linux