CVE-2026-98336: wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: don't offload TC setup on APVLAN interfaces
APVLAN interfaces are purely virtual, so don't try to offload TC setup to drivers. We can't really use the AP interface either since we may not know it all the time, and it could technically even change.
Just reject the TC offload so things get done in software.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Reject TC offload for AP_VLAN interfaces so TC setup is handled in software rather than offloaded to drivers.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel with mac80211 AP_VLAN interfaces and traffic-control (TC) setup are relevant. The issue concerns attempts to offload TC setup from these purely virtual interfaces to wireless drivers.
What behavior does the fix introduce?
The fix rejects TC offload on AP_VLAN interfaces so that TC processing is performed in software instead. It does not attempt to use the associated AP interface for offload, because that interface may be unknown or may change.