CVE-2026-98346

Source
https://cve.org/CVERecord?id=CVE-2026-98346
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98346.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98346
Downstream
Published
2026-10-06T08:46:35Z
Modified
2026-10-08T02:52:57Z
Summary
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: don't get the radio mask for netdev-less wdevs

cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with wdev->netdev, which can be NULL and then crashes in mac80211.

To avoid that, invert the order of checks since wdev->netdev is always valid for beaconing interfaces.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98346.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
abb4cfe3661aa05426916b21164f88ca5a405a3a
Fixed
5b313159c970e945ee125ca87fad0d96ed913e55
Fixed
693d777846d525b8b218bad97a1befa5d9bd4334
Fixed
7166da84a7fe3553f9065782fd80299a37b150e5
Fixed
a7783e585360ee05dfe21d3173dbbe985c94f29e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98346.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98346.json"