CVE-2026-98326
Received Received - Intake

Memory Leak in Linux Kernel WiFi Mesh

Vulnerability report for CVE-2026-98326, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: release the channel if start fails ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting: wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx ieee80211_assign_link_chanctx __ieee80211_link_release_channel ieee80211_link_release_channel ieee80211_teardown_sdata unregister_netdevice_many_notify _cfg80211_unregister_wdev ieee80211_remove_interfaces ieee80211_unregister_hw mac80211_hwsim_del_radio hwsim_exit_net Correctly release the channel on start failures.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 2b5e19677592c167d012c2d129407f39d2bdeb8d
Linux Linux 3.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel occurs in the mac80211 mesh subsystem. When joining a mesh network, the system acquires a channel context but fails to release it if the mesh start process fails. This leads to a resource leak where the channel remains assigned even after the interface is removed, causing a warning in the driver operations.

Detection Guidance

This vulnerability is specific to the Linux kernel's mac80211 mesh functionality. Detection requires checking kernel logs for the described error messages during mesh interface operations. Monitor logs with 'dmesg' or 'journalctl -k' for warnings like 'Failed check-sdata-in-driver check' or 'drv_unassign_vif_chanctx' errors.

Impact Analysis

This vulnerability can cause system instability or crashes when removing mesh network interfaces. It may lead to kernel warnings or errors during interface teardown, potentially disrupting network operations or requiring a system reboot to clear the state.

Mitigation Strategies

Apply the latest Linux kernel update that includes the fix for this issue. If immediate patching isn't possible, disable mesh networking features by unloading the mac80211 module or disabling mesh interfaces until the kernel is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98326. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart