CVE-2026-98327: wifi: mac80211: mesh: reset the CSA state when leaving

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: reset the CSA state when leaving

ifmsh->csa is allocated in ieee80211meshcsabeacon() and only freed in ieee80211meshfinishcsa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it.

Additionally, ifmsh->csarole and ifmsh->chswttl have their state leak in this case, so things can get mixed up in addition to the memory leak.

Refactor the reset and call it in ieee80211stopmesh() to fix it all.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:41 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's mac80211 mesh functionality are affected when a mesh interface leaves while a channel switch announcement is still pending. The issue concerns mesh CSA state handling rather than general Wi-Fi operation.

2

What condition triggers the problem?

The problem occurs when the mesh is stopped or left before an in-progress channel switch completes. In that case, allocated CSA state is not freed and related CSA role and channel-switch TTL state can persist.

3

What are the practical consequences?

The immediate effect is a memory leak. Persisting CSA role and TTL state can also be reused incorrectly, causing mesh channel-switch state to become mixed up after leaving the mesh.

4

What does the fix change?

The fix resets mesh CSA state when the mesh is stopped through ieee80211_stop_mesh(). This frees pending CSA allocation and clears the associated CSA role and channel-switch TTL state.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203