CVE-2026-98340: wifi: cfg80211: only group hidden BSSes with beacon entries

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: only group hidden BSSes with beacon entries

When a probe response for an unknown BSS comes in, cfg80211bssupdate() looks for an existing entry with the same BSSID and a hidden (zero-length or NUL-filled) SSID, and if it finds one it groups them, using the beacon IEs from the existing entry.

But that could find another entry without a beacon, if it was also from a probe response (with SSID), so there's a group without beacon elements.

If a beacon with a hidden SSID for that BSSID arrives later, cfg80211combinebsses() goes looking for the probe response entries that belong to it - i.e. entries with the same BSSID and channel that have no beacon IEs - and finds those two. They are already grouped with each other, so it hits its

WARNONONCE(bss->pub.hiddenbeaconbss) WARNONONCE(!listempty(&bss->hiddenlist))

which are there because an entry without beacon elements is not supposed to be part of a group yet.

Only combine entries when a beacon was already received, ones that are kept separate will be combined when a beacon arrives.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:32 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are needed to trigger the warning?

The issue requires cfg80211 to receive probe responses for an unknown BSS with the same BSSID, including a hidden SSID entry, before a beacon with a hidden SSID for that BSSID arrives. The premature grouping of probe-response-only entries causes the later beacon processing to reach WARN_ON_ONCE conditions.

2

What is the operational impact described?

The described impact is kernel WARN_ON_ONCE warnings during hidden-BSS grouping. The provided information does not describe code execution, privilege escalation, information disclosure, or a denial-of-service outcome.

3

What changes in the resolved version?

The fix prevents cfg80211 from grouping hidden BSS entries unless the existing entry has beacon information. Probe-response-only entries remain separate until a beacon arrives, at which point they can be combined correctly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203