CVE-2026-98334
Received Received - Intake

Kernel State Corruption in Linux mac80211 AP Startup

Vulnerability report for CVE-2026-98334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reset state when starting AP fails ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to: Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00 Call Trace: drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495 ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160 __ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519 ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193 cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538 in hwsim. Also, cfg80211 then allows changing the interface type, and the off-channel path getgs confused about beaconing as well, leading to another warning: WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880 ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122 ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline] __ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882 Reset the state on failures to always have it correct.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
Linux Linux d6a83228823fc0cc8d79d95c9f0bf568b7317862
Linux Linux d6a83228823fc0cc8d79d95c9f0bf568b7317862
Linux Linux d6a83228823fc0cc8d79d95c9f0bf568b7317862
Linux Linux d6a83228823fc0cc8d79d95c9f0bf568b7317862
Linux Linux 3.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel occurs when starting an access point (AP) fails but leaves beaconing state enabled. This can cause a kernel crash (Oops) during scanning operations due to incorrect state handling.

Detection Guidance

This vulnerability is specific to the Linux kernel's mac80211 subsystem and may not have direct detection commands. Monitor kernel logs for divide errors or warnings related to mac80211_hwsim_link_info_changed or drv_link_info_changed. Check for interface state inconsistencies after AP start failures.

Impact Analysis

The vulnerability can cause system crashes (kernel Oops) when scanning for Wi-Fi networks, potentially leading to denial of service. It may also corrupt beaconing state, causing further instability in wireless operations.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. Restart affected wireless interfaces after kernel updates. Monitor system logs for related errors to identify vulnerable configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart