CVE-2026-98339: wifi: cfg80211: don't filter by BSS type when removing stale entries
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: don't filter by BSS type when removing stale entries
When an assoc AP switches to a channel that already has a BSS entry, cfg80211updateassocbssentry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree.
The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211rehashbss() then ran into it:
WARNON(!cmp)
Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using the Linux kernel's cfg80211 Wi-Fi subsystem may be exposed when associating with a rogue access point or device that can trigger a BSS type change during a channel switch.
What does an attacker need to exploit it?
The CVSS vector indicates adjacent-network access with no privileges or user interaction required. The description specifically identifies a rogue AP or device as the trigger source.
What is the observed impact?
A stale BSS entry can remain in the BSS rbtree and cause cfg80211_rehash_bss() to hit a WARN_ON condition. The supplied CVSS rating assesses confidentiality, integrity, and availability impacts as high.
What change resolves the problem?
The fix removes the BSS-type matching requirement when deleting the stale entry, so any entry matching the comparison is removed before the real BSS entry is rehashed.