{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98339","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.342Z","datePublished":"2026-10-06T08:46:29.998Z","dateUpdated":"2026-10-07T06:50:08.023Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:08.023Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: don't filter by BSS type when removing stale entries\n\nWhen an assoc AP switches to a channel that already has a BSS entry,\ncfg80211_update_assoc_bss_entry() removes that entry before rehashing\nthe real one, since the two would otherwise collide in the BSS rbtree.\n\nThe lookup for that entry also required it to match the connection's BSS\ntype, so an entry advertising e.g. the IBSS capability bit was left in\nplace, and the following cfg80211_rehash_bss() then ran into it:\n\n  WARN_ON(!cmp)\n\nChanging the type shouldn't really happen, but can be triggered by a\nrogue AP/device, so drop the check and remove any entries matching\nthe comparison."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The bad state comes from received 802.11 frames: a beacon/probe response carrying the associated AP's BSSID+SSID with the IBSS capability bit on another channel, then a CSA beacon that leads to cfg80211_ch_switch_notify() -> cfg80211_update_assoc_bss_entry(). The attacker must be in WiFi radio range.\nAC:L - The attacker produces every step: injecting the colliding scan entry, sending the CSA (beacons are unprotected without beacon protection), then a second CSA or going silent so connection loss calls cfg80211_unlink_bss(). cmp_bss() ignores capability, so the rb_insert_bss() collision always happens.\nPR:N - No credentials are needed. A rogue AP, or an attacker spoofing management beacons of the victim's AP, triggers mac80211 channel-switch processing and scan-entry creation before any authenticated data exchange.\nUI:N - The victim station only needs to be in its normal associated state. Beacon/CSA processing and the later beacon-loss unlink happen automatically, with no user action.\nS:U - The corruption is confined to cfg80211's BSS list and rbtree within the same kernel. There is no hypervisor or other security-authority boundary crossed.\nC:H - After the failed rehash the connected BSS has stale rbn pointers. A second CSA makes cfg80211_rehash_bss() rb_erase() that non-member node, rewriting live parent/child links so bss_tree can reference entries later freed on expiry. That is a use-after-free on every rb lookup triggered by a received beacon.\nI:H - The double rb_erase() of the stale cbss->rbn and the list_del() leaving poisoned pointers on a still-referenced BSS corrupt kernel heap metadata (tree links, bss_entries). The resulting use-after-free of cfg80211_internal_bss objects is a write-capable memory-corruption primitive.\nA:H - After cfg80211_rehash_bss() list_del()s the connected BSS, beacon-loss handling calls cfg80211_unlink_bss() -> __cfg80211_unlink_bss() -> list_del_init() on LIST_POISON pointers and faults (oops/panic). WARN_ON(!cmp) also panics with panic_on_warn."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/scan.c"],"versions":[{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"6ef87a853327434ae1cd9c5a2c27a557fb4047fc","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"1380ee3a202dbb9f8e8b3c3b87eb410450d57799","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"fb445ec7480da5d2b82bf681e3b4313603722729","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"65fdb973bd905bc3f5cb045a04c1828f2d2a7e24","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"64e23a36d8f04811372365b44cfca325f8e0f4bb","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"6d2fd26185678038ef2ea11dd4d2e6eccbf2dd25","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"0aa44982125c86b47961be5ac1c82eddab8080f3","status":"affected","versionType":"git"},{"version":"0afd425b1b64251f19b5d8d8b49bf56fefbc643f","lessThan":"b377e1000d963e7182a987082b4b06580bd7ac84","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/scan.c"],"versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6ef87a853327434ae1cd9c5a2c27a557fb4047fc"},{"url":"https://git.kernel.org/stable/c/1380ee3a202dbb9f8e8b3c3b87eb410450d57799"},{"url":"https://git.kernel.org/stable/c/fb445ec7480da5d2b82bf681e3b4313603722729"},{"url":"https://git.kernel.org/stable/c/65fdb973bd905bc3f5cb045a04c1828f2d2a7e24"},{"url":"https://git.kernel.org/stable/c/64e23a36d8f04811372365b44cfca325f8e0f4bb"},{"url":"https://git.kernel.org/stable/c/6d2fd26185678038ef2ea11dd4d2e6eccbf2dd25"},{"url":"https://git.kernel.org/stable/c/0aa44982125c86b47961be5ac1c82eddab8080f3"},{"url":"https://git.kernel.org/stable/c/b377e1000d963e7182a987082b4b06580bd7ac84"}],"title":"wifi: cfg80211: don't filter by BSS type when removing stale entries","x_generator":{"engine":"bippy-1.2.0"}}}}