PT-2026-106663 · Linux · Linux
CVE-2026-98334
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: reset state when starting AP fails
ieee80211 start ap() can set enable beacon (and beacon int) and fail
later, leaving it set forever. Scanning can then attempt to restore
beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:mac80211 hwsim link info changed+0xca7/0xf00
Call Trace:
drv link info changed+0x413/0x860 net/mac80211/driver-ops.c:495
ieee80211 link info change notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211 offchannel return+0x381/0x580 net/mac80211/offchannel.c:160
ieee80211 scan completed+0x993/0xe30 net/mac80211/scan.c:519
ieee80211 scan work+0x472/0x2010 net/mac80211/scan.c:1193
cfg80211 wiphy work+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type,
and the off-channel path getgs confused about beaconing as well,
leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drv link info changed+0x583/0x880
ieee80211 link info change notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211 offchannel stop vifs+0x328/0x5c0 net/mac80211/offchannel.c:122
ieee80211 start sw scan net/mac80211/scan.c:583 [inline]
ieee80211 start scan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux