« Volver al listado

CVE-2026-98340

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: only group hidden BSSes with beacon entries

When a probe response for an unknown BSS comes in, __cfg80211_bss_update() looks for an existing entry with the same BSSID and a hidden (zero-length or NUL-filled) SSID, and if it finds one it groups them, using the beacon IEs from the existing entry.

But that could find another entry without a beacon, if it was also from a probe response (with SSID), so there's a group without beacon elements.

If a beacon with a hidden SSID for that BSSID arrives later, cfg80211_combine_bsses() goes looking for the probe response entries that belong to it - i.e. entries with the same BSSID and channel that have no beacon IEs - and finds those two.

Leer descripción completaMostrar menos

They are already grouped with each other, so it hits its

which are there because an entry without beacon elements is not supposed to be part of a group yet.

Only combine entries when a beacon was already received, ones that are kept separate will be combined when a beacon arrives.

Detalles técnicos trazas, registros y código del informe original
  WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
  WARN_ON_ONCE(!list_empty(&bss->hidden_list))

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98340",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "4cd6a518ce7527284bbc9baab5fa2453a7d477c2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "74ed0d992f392c75e1969415527e06df3f7a4034",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "3658093df69849daf4f813a8f087f358e13be203",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "73365b81630b57e1a1f9d50dc87281797855c2ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "7405dd19bda4537a2843637d8d7bed1efd4776cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "86235be788094131912e9bd8412b358d91d99f49",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "332ea1502c46f53375cb109fa82bfaff818f3a41",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4593c4cbe1c96b3995727dc42f6aa103f4ff5afc",
              "lessThan": "068843ed0902c552a13860c5ec6b2ca65b57a065",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/wireless/scan.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/wireless/scan.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:26.720",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/068843ed0902c552a13860c5ec6b2ca65b57a065",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/332ea1502c46f53375cb109fa82bfaff818f3a41",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3658093df69849daf4f813a8f087f358e13be203",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4cd6a518ce7527284bbc9baab5fa2453a7d477c2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/73365b81630b57e1a1f9d50dc87281797855c2ac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7405dd19bda4537a2843637d8d7bed1efd4776cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74ed0d992f392c75e1969415527e06df3f7a4034",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/86235be788094131912e9bd8412b358d91d99f49",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: only group hidden BSSes with beacon entries\n\nWhen a probe response for an unknown BSS comes in, __cfg80211_bss_update()\nlooks for an existing entry with the same BSSID and a hidden (zero-length\nor NUL-filled) SSID, and if it finds one it groups them, using the beacon\nIEs from the existing entry.\n\nBut that could find another entry without a beacon, if it was also from a\nprobe response (with SSID), so there's a group without beacon elements.\n\nIf a beacon with a hidden SSID for that BSSID arrives later,\ncfg80211_combine_bsses() goes looking for the probe response entries that\nbelong to it - i.e. entries with the same BSSID and channel that have no\nbeacon IEs - and finds those two. They are already grouped with each\nother, so it hits its\n\n  WARN_ON_ONCE(bss->pub.hidden_beacon_bss)\n  WARN_ON_ONCE(!list_empty(&bss->hidden_list))\n\nwhich are there because an entry without beacon elements is not supposed\nto be part of a group yet.\n\nOnly combine entries when a beacon was already received, ones that are\nkept separate will be combined when a beacon arrives."
    }
  ],
  "lastModified": "2026-10-06T09:18:26.720",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}