CVE-2026-98334: wifi: mac80211: reset state when starting AP fails

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: reset state when starting AP fails

ieee80211startap() can set enablebeacon (and beaconint) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to:

Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:mac80211hwsimlinkinfochanged+0xca7/0xf00 Call Trace: drvlinkinfochanged+0x413/0x860 net/mac80211/driver-ops.c:495 ieee80211linkinfochangenotify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211offchannelreturn+0x381/0x580 net/mac80211/offchannel.c:160 ieee80211scancompleted+0x993/0xe30 net/mac80211/scan.c:519 ieee80211scanwork+0x472/0x2010 net/mac80211/scan.c:1193 cfg80211wiphywork+0x2b7/0x550 net/wireless/core.c:538

in hwsim. Also, cfg80211 then allows changing the interface type, and the off-channel path getgs confused about beaconing as well, leading to another warning:

WARNING: net/mac80211/driver-ops.c:468 at drvlinkinfochanged+0x583/0x880 ieee80211linkinfochangenotify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211offchannelstopvifs+0x328/0x5c0 net/mac80211/offchannel.c:122 ieee80211startswscan net/mac80211/scan.c:583 [inline] ieee80211startscan+0xfb6/0x1af0 net/mac80211/scan.c:882

Reset the state on failures to always have it correct.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Reset mac80211/hwsim state whenever starting an AP or another operation fails, ensuring enable_beacon and beacon_int are cleared and the state remains correct before scanning or off-channel operations restore it.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are needed to trigger the failure?

The interface must attempt to start an AP and fail after mac80211 has enabled beaconing and set the beacon interval. A subsequent scan or off-channel operation can then act on the stale beaconing state.

2

What is the operational impact of an affected system?

The stale state can cause a divide-error kernel Oops in the mac80211 hwsim path when scanning attempts to restore beaconing. It can also produce warnings and confused beaconing behavior after cfg80211 permits an interface-type change.

3

Are systems that only use Wi-Fi client mode described as affected?

The described trigger depends on a failed attempt to start an AP, followed by scanning or off-channel handling. The provided information does not describe a trigger for interfaces that never attempt AP operation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203