PT-2026-106667 · Linux · Linux
CVE-2026-98338
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: ibss: ref BSS entry for joined event
When the IBSS is joined, we only record the BSSID/channel in the event
and look up the BSS entry when processing it. However, that's racy,
e.g. a new scan with NL80211 SCAN FLAG FLUSH can remove it, causing a
warning in the event work:
!bss
WARNING: net/wireless/ibss.c:37 at cfg80211 ibss joined+0x3d3/0x440
Workqueue: cfg80211 cfg80211 event work
cfg80211 process wdev events+0x39f/0x5b0 net/wireless/util.c:1144
cfg80211 process rdev events+0xa1/0x110 net/wireless/util.c:1179
cfg80211 event work+0x2f/0x40 net/wireless/core.c:393
Do the lookup early (the driver is expected to only join an IBSS that
has a BSS entry) and keep a reference to it.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux