CVE-2026-98338
Received Received - Intake

Linux Kernel IBSS BSS Entry Reference Vulnerability

Vulnerability report for CVE-2026-98338, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: ibss: ref BSS entry for joined event When the IBSS is joined, we only record the BSSID/channel in the event and look up the BSS entry when processing it. However, that's racy, e.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it, causing a warning in the event work: !bss WARNING: net/wireless/ibss.c:37 at __cfg80211_ibss_joined+0x3d3/0x440 Workqueue: cfg80211 cfg80211_event_work cfg80211_process_wdev_events+0x39f/0x5b0 net/wireless/util.c:1144 cfg80211_process_rdev_events+0xa1/0x110 net/wireless/util.c:1179 cfg80211_event_work+0x2f/0x40 net/wireless/core.c:393 Do the lookup early (the driver is expected to only join an IBSS that has a BSS entry) and keep a reference to it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Linux Linux 667503ddcb96f3b10211f997fe55907fa7509841
Linux Linux 667503ddcb96f3b10211f997fe55907fa7509841
Linux Linux 2.6.32

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the IBSS (Independent Basic Service Set) joining process. When a device joins an IBSS network, the system records the BSSID and channel but looks up the BSS entry later. If a scan with NL80211_SCAN_FLAG_FLUSH removes the BSS entry before processing, it triggers a warning in the event work queue.

Detection Guidance

This vulnerability is specific to the Linux kernel's wireless subsystem and may not have direct detection commands. Monitor kernel logs for warnings related to IBSS events or cfg80211 using dmesg or journalctl. Check for crashes or warnings in wireless event processing.

Impact Analysis

This vulnerability may cause system warnings or instability when joining IBSS networks. It could lead to unexpected behavior in wireless networking operations, though it does not directly compromise security or data integrity.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this issue. If immediate patching is not possible, avoid using IBSS (ad-hoc) mode until the update is applied to prevent potential crashes or warnings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98338. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart