CVE-2026-98340

Source
https://cve.org/CVERecord?id=CVE-2026-98340
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98340.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98340
Downstream
Published
2026-10-06T08:46:30Z
Modified
2026-10-08T02:52:57Z
Summary
wifi: cfg80211: only group hidden BSSes with beacon entries
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: only group hidden BSSes with beacon entries

When a probe response for an unknown BSS comes in, __cfg80211_bss_update() looks for an existing entry with the same BSSID and a hidden (zero-length or NUL-filled) SSID, and if it finds one it groups them, using the beacon IEs from the existing entry.

But that could find another entry without a beacon, if it was also from a probe response (with SSID), so there's a group without beacon elements.

If a beacon with a hidden SSID for that BSSID arrives later, cfg80211_combine_bsses() goes looking for the probe response entries that belong to it - i.e. entries with the same BSSID and channel that have no beacon IEs - and finds those two. They are already grouped with each other, so it hits its

WARN_ON_ONCE(bss->pub.hidden_beacon_bss) WARN_ON_ONCE(!list_empty(&bss->hidden_list))

which are there because an entry without beacon elements is not supposed to be part of a group yet.

Only combine entries when a beacon was already received, ones that are kept separate will be combined when a beacon arrives.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98340.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Fixed
4cd6a518ce7527284bbc9baab5fa2453a7d477c2
Fixed
74ed0d992f392c75e1969415527e06df3f7a4034
Fixed
3658093df69849daf4f813a8f087f358e13be203
Fixed
73365b81630b57e1a1f9d50dc87281797855c2ac
Fixed
7405dd19bda4537a2843637d8d7bed1efd4776cf
Fixed
86235be788094131912e9bd8412b358d91d99f49
Fixed
332ea1502c46f53375cb109fa82bfaff818f3a41
Fixed
068843ed0902c552a13860c5ec6b2ca65b57a065

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98340.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.9.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98340.json"