« Volver al listado

CVE-2026-98327

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: reset the CSA state when leaving

ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it.

Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak in this case, so things can get mixed up in addition to the memory leak.

Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98327",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b8456a14e9d2770846fcf74de18ff95b676149a3",
              "lessThan": "aba8dfb45864441199748c33ce3c1c8ca121c8bd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b8456a14e9d2770846fcf74de18ff95b676149a3",
              "lessThan": "bd3b21145ae2e781daac1bbd19216a63ab4e0cbd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b8456a14e9d2770846fcf74de18ff95b676149a3",
              "lessThan": "ba5bf83a81e8832cb84bb3a2da67512f81f57a02",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b8456a14e9d2770846fcf74de18ff95b676149a3",
              "lessThan": "860134b3af77970e006feab7e5decb8c84771c7f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/mac80211/mesh.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mac80211/mesh.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:24.980",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/860134b3af77970e006feab7e5decb8c84771c7f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aba8dfb45864441199748c33ce3c1c8ca121c8bd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba5bf83a81e8832cb84bb3a2da67512f81f57a02",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bd3b21145ae2e781daac1bbd19216a63ab4e0cbd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: mesh: reset the CSA state when leaving\n\nifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed\nin ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.\nLeaving the mesh while a switch is still pending therefore leaks it.\n\nAdditionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak\nin this case, so things can get mixed up in addition to the memory\nleak.\n\nRefactor the reset and call it in ieee80211_stop_mesh() to fix it all."
    }
  ],
  "lastModified": "2026-10-06T09:18:24.980",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}