CVE-2026-98346
Received
Received - Intake
NULL Pointer Dereference in Linux Kernel cfg80211
Vulnerability report for CVE-2026-98346, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with
wdev->netdev, which can be NULL and then crashes in mac80211.
To avoid that, invert the order of checks since wdev->netdev
is always valid for beaconing interfaces.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | abb4cfe3661aa05426916b21164f88ca5a405a3a |
| Linux | Linux | abb4cfe3661aa05426916b21164f88ca5a405a3a |
| Linux | Linux | abb4cfe3661aa05426916b21164f88ca5a405a3a |
| Linux | Linux | abb4cfe3661aa05426916b21164f88ca5a405a3a |
| Linux | Linux | 6.11 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |