CVE-2026-98345: wifi: cfg80211: check IP header size in cfg80211_classify8021d()
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: check IP header size in cfg80211classify8021d()
A frame that looks like IP can be transmitted, but be too short, so the DS field is read incorrectly:
BUG: KMSAN: uninit-value in cfg80211classify8021d+0x99d/0x12b0 net/wireless/util.c:1027 cfg80211classify8021d+0x99d/0x12b0 net/wireless/util.c:1027 ieee80211selectqueue+0x37a/0x9e0 net/mac80211/wme.c:180 ieee80211subifstartxmit+0x60f/0x1d90 net/mac80211/tx.c:4304 ieee80211subifstartxmit+0xa8/0x6d0 net/mac80211/tx.c:4538 ... packetsendmsg+0x9173/0xa2a0 net/packet/afpacket.c:3108
Use skbheaderpointer() like the MPLS case.
Affected Software
Event History
Frequently Asked Questions
What input is needed to trigger the issue?
A transmitted frame must appear to be an IP packet but be shorter than the required IP header size. This can cause cfg80211_classify8021d() to read the DS field incorrectly.
How can I tell whether the issue has been observed on a system?
The reported symptom is a KMSAN uninitialized-value warning in cfg80211_classify8021d() at net/wireless/util.c:1027, with a call path through ieee80211_select_queue() and mac80211 transmission functions.
What code change resolves the problem?
The fix checks the IP header size before accessing it and uses skb_header_pointer(), as is done for the MPLS case. The referenced stable kernel commits contain the resolved change.