CVE-2026-98325
Received Received - Intake

Linux kernel Wi-Fi TX Info Initialization Flaw

Vulnerability report for CVE-2026-98325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: set up the TX info early to fix failure paths The previous commit 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure") cleaned up the leak, but still left the code a bit messy and the failed SKB didn't get reported to userspace. Fix this up by initialising skb->cb[] earlier, which allows using ieee80211_free_txskb() and therefore reports it for the failure in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize() failure path with it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 3.6.3
Linux Linux 3.7
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8
Linux Linux fd39be7ff6f81f2dc91ba6e5f87944abef5b4802

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the mac80211 subsystem related to Wi-Fi TX operations. The issue was that when a TX header build failed, the cleanup process was incomplete, leaving the failed SKB unreported to userspace. The fix initializes the skb->cb[] earlier to allow proper reporting of failures using ieee80211_free_txskb() and unifies failure paths.

Detection Guidance

This vulnerability is specific to the Linux kernel's mac80211 subsystem and may not have direct detection commands. Monitor kernel logs for TX header build failures or SKB leaks in wifi-related operations. Check for kernel messages indicating ieee80211_build_hdr() failures or ieee80211_free_txskb() usage.

Impact Analysis

This vulnerability could lead to improper handling of Wi-Fi transmission failures. If exploited, it might cause unexpected behavior in wireless network operations, such as failed data transmissions not being properly reported or cleaned up. This could result in degraded network performance or instability in systems relying on Wi-Fi connectivity.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. Apply kernel updates from your distribution's official repositories. If using a custom kernel, ensure it includes the commit referenced in the CVE description.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart