CVE-2026-98335

Source
https://cve.org/CVERecord?id=CVE-2026-98335
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98335.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98335
Downstream
Published
2026-10-06T08:46:26Z
Modified
2026-10-08T02:52:57Z
Summary
wifi: mac80211: abort chanswitch when leaving a mesh
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: abort chanswitch when leaving a mesh

The code in ieee80211_stop_mesh() leaves CSA active, but leaving the mesh released the channel context, so the CSA finalize work crashes:

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000003 KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f] RIP: 0010:ieee80211_put_srates_elem+0x42/0x640 net/mac80211/util.c:3272 Call Trace: ieee80211_mesh_build_beacon+0xa83/0x1b50 net/mac80211/mesh.c:1093 ieee80211_mesh_rebuild_beacon+0xc7/0x170 net/mac80211/mesh.c:1147 ieee80211_mesh_finish_csa+0x131/0x210 net/mac80211/mesh.c:1542 ieee80211_set_after_csa_beacon net/mac80211/cfg.c:4085 [inline] __ieee80211_csa_finalize net/mac80211/cfg.c:4133 [inline] ieee80211_csa_finalize+0x633/0x1150 net/mac80211/cfg.c:4155 cfg80211_wiphy_work+0x2ab/0x450 net/wireless/core.c:438

Abort the channel switch properly.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98335.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b8456a14e9d2770846fcf74de18ff95b676149a3
Fixed
bc544ef02327edf61c94d2b6bae9d14b217009b2
Fixed
2e1d6e80148495e728a85a9250176f266312e55c
Fixed
d222fdc973bb8dbf0357772bd9042ffdc8291939
Fixed
ac7472a24bd433b81c06582835dd1d5547c10da9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98335.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98335.json"