PT-2026-106669 · Linux · Linux

CVE-2026-98340

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: only group hidden BSSes with beacon entries
When a probe response for an unknown BSS comes in, cfg80211 bss update() looks for an existing entry with the same BSSID and a hidden (zero-length or NUL-filled) SSID, and if it finds one it groups them, using the beacon IEs from the existing entry.
But that could find another entry without a beacon, if it was also from a probe response (with SSID), so there's a group without beacon elements.
If a beacon with a hidden SSID for that BSSID arrives later, cfg80211 combine bsses() goes looking for the probe response entries that belong to it - i.e. entries with the same BSSID and channel that have no beacon IEs - and finds those two. They are already grouped with each other, so it hits its
WARN ON ONCE(bss->pub.hidden beacon bss) WARN ON ONCE(!list empty(&bss->hidden list))
which are there because an entry without beacon elements is not supposed to be part of a group yet.
Only combine entries when a beacon was already received, ones that are kept separate will be combined when a beacon arrives.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98340

Affected Products

Linux