CVE-2026-98182

Source
https://cve.org/CVERecord?id=CVE-2026-98182
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98182.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98182
Downstream
Published
2026-10-06T08:44:25Z
Modified
2026-10-08T02:52:52Z
Summary
wifi: mac80211: refuse to make a monitor active when it has no queue
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: refuse to make a monitor active when it has no queue

A monitor interface only gets a TXQ if it's created active, and one can't be added later. Setting the flag on a down interface is still allowed, so the driver is handed a monitor with no queue. ath9k dereferences it:

BUG: kernel NULL pointer dereference, address: 0000000000000066 RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k] ath9k_add_interface+0x10c/0x140 [ath9k] drv_add_interface+0x54/0x250 [mac80211] ieee80211_do_open+0x32f/0x800 [mac80211]

Reached with CAP_NET_ADMIN by "iw dev X set monitor active" followed by "ip link set X up". RTNL is held, so netlink operations block behind it.

Refuse the flag when there is no queue to give.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98182.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
79af1f866193de29e65a4dba7d0dab14b0c0ff93
Fixed
b7b7d46ec4fa127767931938b282c361c0519af6
Fixed
abe15e643e576459469867758ae9c586a7bab95d
Fixed
46c223468537a05a404699771cd3e68532dab5e6
Fixed
2b04d6556964ae9f89819b86a0a7801e39c3aae5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98182.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98182.json"