CVE-2026-98326: wifi: mac80211: mesh: release the channel if start fails
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: mesh: release the channel if start fails
ieee80211joinmesh() acquires a channel context and then calls ieee80211startmesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting:
wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:366 at drvunassignvifchanctx ieee80211assignlinkchanctx ieee80211linkreleasechannel ieee80211linkreleasechannel ieee80211teardownsdata unregisternetdevicemanynotify cfg80211unregisterwdev ieee80211removeinterfaces ieee80211unregisterhw mac80211hwsimdelradio hwsimexitnet
Correctly release the channel on start failures.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure the mac80211 mesh start-failure path releases the acquired channel context before interface removal, preventing a later unassign attempt after the channel context has been removed from the driver.