Linux Kernel Vulnerability in Wireless Configuration and Management
CVE-2026-98339

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98339?

A vulnerability in the Linux kernel's cfg80211 wireless configuration subsystem allows for improper removal of stale BSS entries. When an associated access point (AP) switches channels, the system should clear any existing BSS entries to prevent collisions. However, due to a filter by BSS type during the removal process, some entries, especially those related to rogue APs, may be left unaddressed. This can lead to unexpected behavior during connection management and may allow attackers to exploit these stale entries.

Affected Version(s)

Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f < 6ef87a853327434ae1cd9c5a2c27a557fb4047fc

Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f < 1380ee3a202dbb9f8e8b3c3b87eb410450d57799

Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.