CVE-2026-98337

Source
https://cve.org/CVERecord?id=CVE-2026-98337
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98337.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98337
Downstream
Published
2026-10-06T08:46:28Z
Modified
2026-10-07T02:47:34Z
Summary
wifi: mac80211: don't start a ROC while scanning
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't start a ROC while scanning

The ROC work can be pending when a scan starts (which requires ROC list to be empty, but that's possible), and then a new ROC can be added to the list and the work will pick it up.

Avoid starting that ROC if a scan made it between things, as otherwise we'll hit a warning later:

WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0 Workqueue: events_unbound cfg80211_wiphy_work Call Trace: __ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537 ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193 cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98337.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
aaa016ccd5df89d73483d0d51ee1f692978ccc35
Fixed
5dc8ec2f8d1d62914661577c23ec151f5c9734a4
Fixed
81baab8b645ec532bad2b7a8464191c720ef8fd9
Fixed
58b806f699052c572dec6cab2c376f884f27e98f
Fixed
733f0fde95392ed5f61a4e36aee661ea8d0e8581

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98337.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98337.json"