CVE-2026-98339
Received Received - Intake

WiFi BSS Entry Removal Flaw in Linux Kernel

Vulnerability report for CVE-2026-98339, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't filter by BSS type when removing stale entries When an assoc AP switches to a channel that already has a BSS entry, cfg80211_update_assoc_bss_entry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree. The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211_rehash_bss() then ran into it: WARN_ON(!cmp) Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f
Linux Linux 5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the wifi configuration subsystem (cfg80211). When an access point (AP) switches to a channel with an existing BSS entry, the system attempts to remove the old entry before adding the new one. However, the removal process incorrectly filtered entries by BSS type, leaving some stale entries in place. This caused a warning during rehashing and could lead to unexpected behavior in wireless network management.

Detection Guidance

This vulnerability is specific to the Linux kernel's wifi subsystem and may not have direct detection commands. Monitor kernel logs for warnings related to cfg80211 or BSS entry handling. Check for unusual AP behavior or channel switching issues in wireless network logs.

Impact Analysis

This vulnerability could affect users by causing instability in wireless network connections. It may lead to unexpected disconnections, reduced network performance, or errors in managing wireless access points. Systems relying on Linux kernel wifi functionality could experience crashes or misbehavior when handling AP transitions between channels.

Mitigation Strategies

Update your Linux kernel to the latest patched version. If using a distribution kernel, apply vendor-provided updates. For custom kernels, apply the upstream patch addressing the cfg80211 BSS entry handling issue. Restart systems after updates to ensure changes take effect.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98339. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart