CVE-2026-98329: wifi: mac80211: don't allow injecting frames wider than the chanctx
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: don't allow injecting frames wider than the chanctx
Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.
If the bandwidth requested is too wide, that triggers a warning in hwsim:
WARNON(hwsimgetchanwidth(bw) > hwsimgetchanwidth(confbw))
Drop such frames entirely instead since they cannot be sent.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Drop injected monitor-interface frames that request a bandwidth wider than the channel context, since they cannot be sent.