CVE-2026-98345: wifi: cfg80211: check IP header size in cfg80211_classify8021d()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: check IP header size in cfg80211classify8021d()

A frame that looks like IP can be transmitted, but be too short, so the DS field is read incorrectly:

BUG: KMSAN: uninit-value in cfg80211classify8021d+0x99d/0x12b0 net/wireless/util.c:1027 cfg80211classify8021d+0x99d/0x12b0 net/wireless/util.c:1027 ieee80211selectqueue+0x37a/0x9e0 net/mac80211/wme.c:180 ieee80211subifstartxmit+0x60f/0x1d90 net/mac80211/tx.c:4304 ieee80211subifstartxmit+0xa8/0x6d0 net/mac80211/tx.c:4538 ... packetsendmsg+0x9173/0xa2a0 net/packet/afpacket.c:3108

Use skbheaderpointer() like the MPLS case.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What input is needed to trigger the issue?

A transmitted frame must appear to be an IP packet but be shorter than the required IP header size. This can cause cfg80211_classify8021d() to read the DS field incorrectly.

2

How can I tell whether the issue has been observed on a system?

The reported symptom is a KMSAN uninitialized-value warning in cfg80211_classify8021d() at net/wireless/util.c:1027, with a call path through ieee80211_select_queue() and mac80211 transmission functions.

3

What code change resolves the problem?

The fix checks the IP header size before accessing it and uses skb_header_pointer(), as is done for the MPLS case. The referenced stable kernel commits contain the resolved change.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203