CVE-2026-98327: wifi: mac80211: mesh: reset the CSA state when leaving
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: mesh: reset the CSA state when leaving
ifmsh->csa is allocated in ieee80211meshcsabeacon() and only freed in ieee80211meshfinishcsa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it.
Additionally, ifmsh->csarole and ifmsh->chswttl have their state leak in this case, so things can get mixed up in addition to the memory leak.
Refactor the reset and call it in ieee80211stopmesh() to fix it all.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel's mac80211 mesh functionality are affected when a mesh interface leaves while a channel switch announcement is still pending. The issue concerns mesh CSA state handling rather than general Wi-Fi operation.
What condition triggers the problem?
The problem occurs when the mesh is stopped or left before an in-progress channel switch completes. In that case, allocated CSA state is not freed and related CSA role and channel-switch TTL state can persist.
What are the practical consequences?
The immediate effect is a memory leak. Persisting CSA role and TTL state can also be reused incorrectly, causing mesh channel-switch state to become mixed up after leaving the mesh.
What does the fix change?
The fix resets mesh CSA state when the mesh is stopped through ieee80211_stop_mesh(). This frees pending CSA allocation and clears the associated CSA role and channel-switch TTL state.