« Volver al listado

CVE-2026-98329

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't allow injecting frames wider than the chanctx

Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.

If the bandwidth requested is too wide, that triggers a warning in hwsim:

Drop such frames entirely instead since they cannot be sent.

Detalles técnicos trazas, registros y código del informe original
  WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98329",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "646e76bb5daf4ca38438c69ffb72cccb605f3466",
              "lessThan": "a5c715eda066cba5ce3372759188ba8636dca629",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "646e76bb5daf4ca38438c69ffb72cccb605f3466",
              "lessThan": "73f48f7e16cadfc74f444ccd10c1d3ae253e2e27",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "646e76bb5daf4ca38438c69ffb72cccb605f3466",
              "lessThan": "c69718519a81e87284494d0c6e6eb7bdd834707a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "646e76bb5daf4ca38438c69ffb72cccb605f3466",
              "lessThan": "e14bf37bb2b3853012ff160131d1c6233f7a9cc9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/net/mac80211.h",
            "net/mac80211/iface.c",
            "net/mac80211/tx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/mac80211.h",
            "net/mac80211/iface.c",
            "net/mac80211/tx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:25.250",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/73f48f7e16cadfc74f444ccd10c1d3ae253e2e27",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a5c715eda066cba5ce3372759188ba8636dca629",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c69718519a81e87284494d0c6e6eb7bdd834707a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e14bf37bb2b3853012ff160131d1c6233f7a9cc9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't allow injecting frames wider than the chanctx\n\nFrames injected on a monitor interface can carry a radiotap\nfield requesting a bandwidth, which mac80211 passes down to\nthe driver regardless of the the actual operational bandwidth.\n\nIf the bandwidth requested is too wide, that triggers a warning\nin hwsim:\n\n  WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))\n\nDrop such frames entirely instead since they cannot be sent."
    }
  ],
  "lastModified": "2026-10-06T09:18:25.250",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}