CVE-2026-98339: wifi: cfg80211: don't filter by BSS type when removing stale entries

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: don't filter by BSS type when removing stale entries

When an assoc AP switches to a channel that already has a BSS entry, cfg80211updateassocbssentry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree.

The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211rehashbss() then ran into it:

WARNON(!cmp)

Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverity
Data Sourced
via NVD·09:18 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:20 AM
DescriptionSeverityWeakness
Sep 6, 58736
Event
via FIRST·11:07 PM

Frequently Asked Questions

1

Who is exposed to this issue?

Systems using the Linux kernel's cfg80211 Wi-Fi subsystem may be exposed when associating with a rogue access point or device that can trigger a BSS type change during a channel switch.

2

What does an attacker need to exploit it?

The CVSS vector indicates adjacent-network access with no privileges or user interaction required. The description specifically identifies a rogue AP or device as the trigger source.

3

What is the observed impact?

A stale BSS entry can remain in the BSS rbtree and cause cfg80211_rehash_bss() to hit a WARN_ON condition. The supplied CVSS rating assesses confidentiality, integrity, and availability impacts as high.

4

What change resolves the problem?

The fix removes the BSS-type matching requirement when deleting the stale entry, so any entry matching the comparison is removed before the real BSS entry is rehashed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203