<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 13:46:59 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-98340 — wifi: cfg80211: only group hidden BSSes with beacon entries</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-98340</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: cfg80211: only group hidden BSSes with beacon entries&lt;/p&gt;
&lt;p&gt;When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.&lt;/p&gt;
&lt;p&gt;But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there&amp;#39;s a group without beacon elements.&lt;/p&gt;
&lt;p&gt;If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its&lt;/p&gt;
&lt;p&gt;WARN_ON_ONCE(bss-&amp;gt;pub.hidden_beacon_bss)
  WARN_ON_ONCE(!list_empty(&amp;amp;bss-&amp;gt;hidden_list))&lt;/p&gt;
&lt;p&gt;which are there because an entry without beacon elements is not supposed
to be part of a group yet.&lt;/p&gt;
&lt;p&gt;Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: cfg80211: only group hidden BSSes with beacon entries&lt;/p&gt;
&lt;p&gt;When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.&lt;/p&gt;
&lt;p&gt;But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there&amp;#39;s a group without beacon elements.&lt;/p&gt;
&lt;p&gt;If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its&lt;/p&gt;
&lt;p&gt;WARN_ON_ONCE(bss-&amp;gt;pub.hidden_beacon_bss)
  WARN_ON_ONCE(!list_empty(&amp;amp;bss-&amp;gt;hidden_list))&lt;/p&gt;
&lt;p&gt;which are there because an entry without beacon elements is not supposed
to be part of a group yet.&lt;/p&gt;
&lt;p&gt;Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-98340</guid>
    </item>
  </channel>
</rss>
