CVE-2026-98328
Received
Received - Intake
Buffer Overflow in Linux Kernel WiFi Driver
Vulnerability report for CVE-2026-98328, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: add HE 6 GHz capability in the scan elems len
The HE 6 GHz Band Capability element is in the probe request for
every band if 6 GHz is supported, so add the size to scan_ies_len.
Otherwise, building probe request elements can fail, triggering the
WARN_ON in __ieee80211_start_scan().
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 2ad2274c58ee2dcaf9ccde5c63ff30f59b138f77 |
| Linux | Linux | 5.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |