CVE-2026-98334: wifi: mac80211: reset state when starting AP fails
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: reset state when starting AP fails
ieee80211startap() can set enablebeacon (and beaconint) and fail later, leaving it set forever. Scanning can then attempt to restore beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:mac80211hwsimlinkinfochanged+0xca7/0xf00 Call Trace: drvlinkinfochanged+0x413/0x860 net/mac80211/driver-ops.c:495 ieee80211linkinfochangenotify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211offchannelreturn+0x381/0x580 net/mac80211/offchannel.c:160 ieee80211scancompleted+0x993/0xe30 net/mac80211/scan.c:519 ieee80211scanwork+0x472/0x2010 net/mac80211/scan.c:1193 cfg80211wiphywork+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type, and the off-channel path getgs confused about beaconing as well, leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drvlinkinfochanged+0x583/0x880 ieee80211linkinfochangenotify+0x24b/0x3c0 net/mac80211/main.c:427 ieee80211offchannelstopvifs+0x328/0x5c0 net/mac80211/offchannel.c:122 ieee80211startswscan net/mac80211/scan.c:583 [inline] ieee80211startscan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Reset mac80211/hwsim state whenever starting an AP or another operation fails, ensuring enable_beacon and beacon_int are cleared and the state remains correct before scanning or off-channel operations restore it.
Event History
Frequently Asked Questions
What conditions are needed to trigger the failure?
The interface must attempt to start an AP and fail after mac80211 has enabled beaconing and set the beacon interval. A subsequent scan or off-channel operation can then act on the stale beaconing state.
What is the operational impact of an affected system?
The stale state can cause a divide-error kernel Oops in the mac80211 hwsim path when scanning attempts to restore beaconing. It can also produce warnings and confused beaconing behavior after cfg80211 permits an interface-type change.
Are systems that only use Wi-Fi client mode described as affected?
The described trigger depends on a failed attempt to start an AP, followed by scanning or off-channel handling. The provided information does not describe a trigger for interfaces that never attempt AP operation.