Linux Kernel Vulnerability in Wireless Protocol Handling
CVE-2026-98345

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98345?

A vulnerability exists in the Linux kernel's wireless subsystem that could lead to an improper handling of IP header sizes. Specifically, the cfg80211_classify8021d() function may read an improperly sized Data Structure (DS) field from frames that appear to be IP but do not meet the required length. This issue can cause uninitialized memory values to be accessed, potentially compromising system integrity. The vulnerability emphasizes the need for robust validation to prevent such discrepancies in the handling of wireless communication frames.

Affected Version(s)

Linux e31a16d6f64ef0e324c6f54d5112703c3f13a9c4 < 18d5547327c202cda33ad2bbd203220c2c62c8a7

Linux e31a16d6f64ef0e324c6f54d5112703c3f13a9c4 < 3ff17ffa8d02e0e3f6b2f6e57af4aac511f5b734

Linux e31a16d6f64ef0e324c6f54d5112703c3f13a9c4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.