CVE-2026-98340 (GCVE-0-2026-98340)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:46 – Updated: 2026-10-06 08:46
VLAI
Title
wifi: cfg80211: only group hidden BSSes with beacon entries
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: only group hidden BSSes with beacon entries When a probe response for an unknown BSS comes in, __cfg80211_bss_update() looks for an existing entry with the same BSSID and a hidden (zero-length or NUL-filled) SSID, and if it finds one it groups them, using the beacon IEs from the existing entry. But that could find another entry without a beacon, if it was also from a probe response (with SSID), so there's a group without beacon elements. If a beacon with a hidden SSID for that BSSID arrives later, cfg80211_combine_bsses() goes looking for the probe response entries that belong to it - i.e. entries with the same BSSID and channel that have no beacon IEs - and finds those two. They are already grouped with each other, so it hits its WARN_ON_ONCE(bss->pub.hidden_beacon_bss) WARN_ON_ONCE(!list_empty(&bss->hidden_list)) which are there because an entry without beacon elements is not supposed to be part of a group yet. Only combine entries when a beacon was already received, ones that are kept separate will be combined when a beacon arrives.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 4cd6a518ce7527284bbc9baab5fa2453a7d477c2 (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 74ed0d992f392c75e1969415527e06df3f7a4034 (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 3658093df69849daf4f813a8f087f358e13be203 (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 73365b81630b57e1a1f9d50dc87281797855c2ac (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 7405dd19bda4537a2843637d8d7bed1efd4776cf (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 86235be788094131912e9bd8412b358d91d99f49 (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 332ea1502c46f53375cb109fa82bfaff818f3a41 (git)
Affected: 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc , < 068843ed0902c552a13860c5ec6b2ca65b57a065 (git)
Create a notification for this product.
Linux Linux Affected: 3.9
Unaffected: 0 , < 3.9 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/wireless/scan.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4cd6a518ce7527284bbc9baab5fa2453a7d477c2",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "74ed0d992f392c75e1969415527e06df3f7a4034",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "3658093df69849daf4f813a8f087f358e13be203",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "73365b81630b57e1a1f9d50dc87281797855c2ac",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "7405dd19bda4537a2843637d8d7bed1efd4776cf",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "86235be788094131912e9bd8412b358d91d99f49",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "332ea1502c46f53375cb109fa82bfaff818f3a41",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            },
            {
              "lessThan": "068843ed0902c552a13860c5ec6b2ca65b57a065",
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/wireless/scan.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "lessThan": "3.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "3.9",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: only group hidden BSSes with beacon entries\n\nWhen a probe response for an unknown BSS comes in, __cfg80211_bss_update()\nlooks for an existing entry with the same BSSID and a hidden (zero-length\nor NUL-filled) SSID, and if it finds one it groups them, using the beacon\nIEs from the existing entry.\n\nBut that could find another entry without a beacon, if it was also from a\nprobe response (with SSID), so there\u0027s a group without beacon elements.\n\nIf a beacon with a hidden SSID for that BSSID arrives later,\ncfg80211_combine_bsses() goes looking for the probe response entries that\nbelong to it - i.e. entries with the same BSSID and channel that have no\nbeacon IEs - and finds those two. They are already grouped with each\nother, so it hits its\n\n  WARN_ON_ONCE(bss-\u003epub.hidden_beacon_bss)\n  WARN_ON_ONCE(!list_empty(\u0026bss-\u003ehidden_list))\n\nwhich are there because an entry without beacon elements is not supposed\nto be part of a group yet.\n\nOnly combine entries when a beacon was already received, ones that are\nkept separate will be combined when a beacon arrives."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:46:30.796Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4cd6a518ce7527284bbc9baab5fa2453a7d477c2"
        },
        {
          "url": "https://git.kernel.org/stable/c/74ed0d992f392c75e1969415527e06df3f7a4034"
        },
        {
          "url": "https://git.kernel.org/stable/c/3658093df69849daf4f813a8f087f358e13be203"
        },
        {
          "url": "https://git.kernel.org/stable/c/73365b81630b57e1a1f9d50dc87281797855c2ac"
        },
        {
          "url": "https://git.kernel.org/stable/c/7405dd19bda4537a2843637d8d7bed1efd4776cf"
        },
        {
          "url": "https://git.kernel.org/stable/c/86235be788094131912e9bd8412b358d91d99f49"
        },
        {
          "url": "https://git.kernel.org/stable/c/332ea1502c46f53375cb109fa82bfaff818f3a41"
        },
        {
          "url": "https://git.kernel.org/stable/c/068843ed0902c552a13860c5ec6b2ca65b57a065"
        }
      ],
      "title": "wifi: cfg80211: only group hidden BSSes with beacon entries",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98340",
    "datePublished": "2026-10-06T08:46:30.796Z",
    "dateReserved": "2026-09-25T10:25:14.342Z",
    "dateUpdated": "2026-10-06T08:46:30.796Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98340",
      "date": "2026-10-08",
      "epss": "0.00184",
      "percentile": "0.0734"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/wireless/scan.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "4cd6a518ce7527284bbc9baab5fa2453a7d477c2",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "74ed0d992f392c75e1969415527e06df3f7a4034",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "3658093df69849daf4f813a8f087f358e13be203",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "73365b81630b57e1a1f9d50dc87281797855c2ac",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "7405dd19bda4537a2843637d8d7bed1efd4776cf",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "86235be788094131912e9bd8412b358d91d99f49",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "332ea1502c46f53375cb109fa82bfaff818f3a41",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "068843ed0902c552a13860c5ec6b2ca65b57a065",
                    "status": "affected",
                    "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/wireless/scan.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.9"
                  },
                  {
                    "lessThan": "3.9",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: only group hidden BSSes with beacon entries\n\nWhen a probe response for an unknown BSS comes in, __cfg80211_bss_update()\nlooks for an existing entry with the same BSSID and a hidden (zero-length\nor NUL-filled) SSID, and if it finds one it groups them, using the beacon\nIEs from the existing entry.\n\nBut that could find another entry without a beacon, if it was also from a\nprobe response (with SSID), so there\u0027s a group without beacon elements.\n\nIf a beacon with a hidden SSID for that BSSID arrives later,\ncfg80211_combine_bsses() goes looking for the probe response entries that\nbelong to it - i.e. entries with the same BSSID and channel that have no\nbeacon IEs - and finds those two. They are already grouped with each\nother, so it hits its\n\n  WARN_ON_ONCE(bss-\u003epub.hidden_beacon_bss)\n  WARN_ON_ONCE(!list_empty(\u0026bss-\u003ehidden_list))\n\nwhich are there because an entry without beacon elements is not supposed\nto be part of a group yet.\n\nOnly combine entries when a beacon was already received, ones that are\nkept separate will be combined when a beacon arrives."
          }
        ],
        "id": "CVE-2026-98340",
        "lastModified": "2026-10-06T09:18:26.720",
        "metrics": {},
        "published": "2026-10-06T09:18:26.720",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/068843ed0902c552a13860c5ec6b2ca65b57a065"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/332ea1502c46f53375cb109fa82bfaff818f3a41"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/3658093df69849daf4f813a8f087f358e13be203"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/4cd6a518ce7527284bbc9baab5fa2453a7d477c2"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/73365b81630b57e1a1f9d50dc87281797855c2ac"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/7405dd19bda4537a2843637d8d7bed1efd4776cf"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/74ed0d992f392c75e1969415527e06df3f7a4034"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/86235be788094131912e9bd8412b358d91d99f49"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:47:11Z",
      "cve": "CVE-2026-98340",
      "id": "CVE-2026-98340",
      "initial_release_date": "2026-10-08T16:47:11Z",
      "product_status:known_affected": "297",
      "product_status:known_not_affected": "50",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98340",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98340.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…