CVE-2026-98329

Source
https://cve.org/CVERecord?id=CVE-2026-98329
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98329.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98329
Downstream
Published
2026-10-06T08:46:21Z
Modified
2026-10-08T02:52:57Z
Summary
wifi: mac80211: don't allow injecting frames wider than the chanctx
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't allow injecting frames wider than the chanctx

Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.

If the bandwidth requested is too wide, that triggers a warning in hwsim:

WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))

Drop such frames entirely instead since they cannot be sent.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98329.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
646e76bb5daf4ca38438c69ffb72cccb605f3466
Fixed
a5c715eda066cba5ce3372759188ba8636dca629
Fixed
73f48f7e16cadfc74f444ccd10c1d3ae253e2e27
Fixed
c69718519a81e87284494d0c6e6eb7bdd834707a
Fixed
e14bf37bb2b3853012ff160131d1c6233f7a9cc9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98329.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98329.json"