« Volver al listado

CVE-2026-98334

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: reset state when starting AP fails

ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to:

in hwsim. Also, cfg80211 then allows changing the interface type, and the off-channel path getgs confused about beaconing as well, leading to another warning:

Reset the state on failures to always have it correct.

Detalles técnicos trazas, registros y código del informe original
  Oops: divide error: 0000 [#1] SMP KASAN NOPTI
  RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00
  Call Trace:
   drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495
   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
   ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160
   __ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519
   ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193
   cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538

  WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880
   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
   ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122
   ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]
   __ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98334",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d6a83228823fc0cc8d79d95c9f0bf568b7317862",
              "lessThan": "d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6a83228823fc0cc8d79d95c9f0bf568b7317862",
              "lessThan": "5d5ff5b36f5748a2a077f875a73ccb26860d3fcc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6a83228823fc0cc8d79d95c9f0bf568b7317862",
              "lessThan": "6eac225f59c1c2277ac74f8a716d6df0ba3b8d28",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6a83228823fc0cc8d79d95c9f0bf568b7317862",
              "lessThan": "3f28551d0241254a75626d868041c6340285088b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mac80211/cfg.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:25.903",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3f28551d0241254a75626d868041c6340285088b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5d5ff5b36f5748a2a077f875a73ccb26860d3fcc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6eac225f59c1c2277ac74f8a716d6df0ba3b8d28",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: reset state when starting AP fails\n\nieee80211_start_ap() can set enable_beacon (and beacon_int) and fail\nlater, leaving it set forever. Scanning can then attempt to restore\nbeaconing on such an interface, leading to:\n\n  Oops: divide error: 0000 [#1] SMP KASAN NOPTI\n  RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00\n  Call Trace:\n   drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160\n   __ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519\n   ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193\n   cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538\n\nin hwsim. Also, cfg80211 then allows changing the interface type,\nand the off-channel path getgs confused about beaconing as well,\nleading to another warning:\n\n  WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122\n   ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]\n   __ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882\n\nReset the state on failures to always have it correct."
    }
  ],
  "lastModified": "2026-10-06T09:18:25.903",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}