Linux Kernel Vulnerability in Wireless Connectivity by Linux Foundation
CVE-2026-98338
What is CVE-2026-98338?
A vulnerability exists in the Linux kernel that affects wireless networking functionality, specifically within the cfg80211 subsystem. When an Independent Basic Service Set (IBSS) is joined, the system fails to maintain a reliable reference to the Basic Service Set (BSS) entry associated with the event, particularly when a new scan is initiated that can lead to race conditions. This could result in unexpected behavior, including warnings and potential instability in wireless communications, as the BSS entry may be inadvertently removed. The issue is addressed by ensuring the lookup of the BSS entry occurs early in the join process, thereby maintaining the necessary reference and preventing race conditions.
Affected Version(s)
Linux 667503ddcb96f3b10211f997fe55907fa7509841
Linux 667503ddcb96f3b10211f997fe55907fa7509841 < 708f9d43d6a2eb9c6b83fe62af628de9dffd9314
Linux 2.6.32