PT-2026-106663 · Linux · Linux

CVE-2026-98334

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: reset state when starting AP fails
ieee80211 start ap() can set enable beacon (and beacon int) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:mac80211 hwsim link info changed+0xca7/0xf00 Call Trace: drv link info changed+0x413/0x860 net/mac80211/driver-ops.c:495 ieee80211 link info change notify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211 offchannel return+0x381/0x580 net/mac80211/offchannel.c:160 ieee80211 scan completed+0x993/0xe30 net/mac80211/scan.c:519 ieee80211 scan work+0x472/0x2010 net/mac80211/scan.c:1193 cfg80211 wiphy work+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type, and the off-channel path getgs confused about beaconing as well, leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drv link info changed+0x583/0x880 ieee80211 link info change notify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211 offchannel stop vifs+0x328/0x5c0 net/mac80211/offchannel.c:122 ieee80211 start sw scan net/mac80211/scan.c:583 [inline] ieee80211 start scan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98334

Affected Products

Linux