CVE-2026-98327

Source
https://cve.org/CVERecord?id=CVE-2026-98327
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98327.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98327
Downstream
Published
2026-10-06T08:46:20Z
Modified
2026-10-07T02:47:34Z
Summary
wifi: mac80211: mesh: reset the CSA state when leaving
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: reset the CSA state when leaving

ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it.

Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak in this case, so things can get mixed up in addition to the memory leak.

Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98327.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b8456a14e9d2770846fcf74de18ff95b676149a3
Fixed
aba8dfb45864441199748c33ce3c1c8ca121c8bd
Fixed
bd3b21145ae2e781daac1bbd19216a63ab4e0cbd
Fixed
ba5bf83a81e8832cb84bb3a2da67512f81f57a02
Fixed
860134b3af77970e006feab7e5decb8c84771c7f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98327.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98327.json"