CVE-2026-98326 (GCVE-0-2026-98326)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:46 – Updated: 2026-10-06 08:46
VLAI
Title
wifi: mac80211: mesh: release the channel if start fails
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: release the channel if start fails ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting: wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx ieee80211_assign_link_chanctx __ieee80211_link_release_channel ieee80211_link_release_channel ieee80211_teardown_sdata unregister_netdevice_many_notify _cfg80211_unregister_wdev ieee80211_remove_interfaces ieee80211_unregister_hw mac80211_hwsim_del_radio hwsim_exit_net Correctly release the channel on start failures.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < f0afcec2129c166e61821d6ae097061155f01b12 (git)
Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < b51f5a310bd6888b90bb9546a8081215dcfe6fbe (git)
Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < 632f7acfe6dac1278a9314eaaab14fada400ddaf (git)
Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < 41bee71112db53651ba9a9030de1b843255a4a7f (git)
Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < 4a4e3fa77ea36d3419d806fb5883ef425a605a5d (git)
Affected: 2b5e19677592c167d012c2d129407f39d2bdeb8d , < ae97fff6495a8764bc0ef281cfe5444f701e527f (git)
Create a notification for this product.
Linux Linux Affected: 3.9
Unaffected: 0 , < 3.9 (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f0afcec2129c166e61821d6ae097061155f01b12",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            },
            {
              "lessThan": "b51f5a310bd6888b90bb9546a8081215dcfe6fbe",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            },
            {
              "lessThan": "632f7acfe6dac1278a9314eaaab14fada400ddaf",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            },
            {
              "lessThan": "41bee71112db53651ba9a9030de1b843255a4a7f",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            },
            {
              "lessThan": "4a4e3fa77ea36d3419d806fb5883ef425a605a5d",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            },
            {
              "lessThan": "ae97fff6495a8764bc0ef281cfe5444f701e527f",
              "status": "affected",
              "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "lessThan": "3.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: mesh: release the channel if start fails\n\nieee80211_join_mesh() acquires a channel context and then calls\nieee80211_start_mesh(), which can fail. In that case, the chanctx\nisn\u0027t released then interface removal will attempt to unassign it\nafter it\u0027s removed from the driver, hitting:\n\n  wlan0: Failed check-sdata-in-driver check, flags: 0x0\n  WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx\n   ieee80211_assign_link_chanctx\n   __ieee80211_link_release_channel\n   ieee80211_link_release_channel\n   ieee80211_teardown_sdata\n   unregister_netdevice_many_notify\n   _cfg80211_unregister_wdev\n   ieee80211_remove_interfaces\n   ieee80211_unregister_hw\n   mac80211_hwsim_del_radio\n   hwsim_exit_net\n\nCorrectly release the channel on start failures."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:46:19.534Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f0afcec2129c166e61821d6ae097061155f01b12"
        },
        {
          "url": "https://git.kernel.org/stable/c/b51f5a310bd6888b90bb9546a8081215dcfe6fbe"
        },
        {
          "url": "https://git.kernel.org/stable/c/632f7acfe6dac1278a9314eaaab14fada400ddaf"
        },
        {
          "url": "https://git.kernel.org/stable/c/41bee71112db53651ba9a9030de1b843255a4a7f"
        },
        {
          "url": "https://git.kernel.org/stable/c/4a4e3fa77ea36d3419d806fb5883ef425a605a5d"
        },
        {
          "url": "https://git.kernel.org/stable/c/ae97fff6495a8764bc0ef281cfe5444f701e527f"
        }
      ],
      "title": "wifi: mac80211: mesh: release the channel if start fails",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98326",
    "datePublished": "2026-10-06T08:46:19.534Z",
    "dateReserved": "2026-09-25T10:25:14.340Z",
    "dateUpdated": "2026-10-06T08:46:19.534Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98326",
      "date": "2026-10-08",
      "epss": "0.0018",
      "percentile": "0.06949"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/mac80211/cfg.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "f0afcec2129c166e61821d6ae097061155f01b12",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b51f5a310bd6888b90bb9546a8081215dcfe6fbe",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "632f7acfe6dac1278a9314eaaab14fada400ddaf",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "41bee71112db53651ba9a9030de1b843255a4a7f",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4a4e3fa77ea36d3419d806fb5883ef425a605a5d",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ae97fff6495a8764bc0ef281cfe5444f701e527f",
                    "status": "affected",
                    "version": "2b5e19677592c167d012c2d129407f39d2bdeb8d",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/mac80211/cfg.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.9"
                  },
                  {
                    "lessThan": "3.9",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: mesh: release the channel if start fails\n\nieee80211_join_mesh() acquires a channel context and then calls\nieee80211_start_mesh(), which can fail. In that case, the chanctx\nisn\u0027t released then interface removal will attempt to unassign it\nafter it\u0027s removed from the driver, hitting:\n\n  wlan0: Failed check-sdata-in-driver check, flags: 0x0\n  WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx\n   ieee80211_assign_link_chanctx\n   __ieee80211_link_release_channel\n   ieee80211_link_release_channel\n   ieee80211_teardown_sdata\n   unregister_netdevice_many_notify\n   _cfg80211_unregister_wdev\n   ieee80211_remove_interfaces\n   ieee80211_unregister_hw\n   mac80211_hwsim_del_radio\n   hwsim_exit_net\n\nCorrectly release the channel on start failures."
          }
        ],
        "id": "CVE-2026-98326",
        "lastModified": "2026-10-06T09:18:24.840",
        "metrics": {},
        "published": "2026-10-06T09:18:24.840",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/41bee71112db53651ba9a9030de1b843255a4a7f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/4a4e3fa77ea36d3419d806fb5883ef425a605a5d"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/632f7acfe6dac1278a9314eaaab14fada400ddaf"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ae97fff6495a8764bc0ef281cfe5444f701e527f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b51f5a310bd6888b90bb9546a8081215dcfe6fbe"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/f0afcec2129c166e61821d6ae097061155f01b12"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "low",
      "current_release_date": "2026-10-08T16:47:30Z",
      "cve": "CVE-2026-98326",
      "id": "CVE-2026-98326",
      "initial_release_date": "2026-10-08T16:47:30Z",
      "product_status:known_affected": "297",
      "product_status:known_not_affected": "50",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98326",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98326.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…