CVE-2026-98346: wifi: cfg80211: don't get the radio mask for netdev-less wdevs
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
cfg80211calculatebidata() calls rdevgetradiomask() with wdev->netdev, which can be NULL and then crashes in mac80211.
To avoid that, invert the order of checks since wdev->netdev is always valid for beaconing interfaces.
Affected Software
Event History
Frequently Asked Questions
What systems are exposed to this crash?
Linux kernel systems using cfg80211/mac80211 wireless functionality are exposed when cfg80211_calculate_bi_data() processes a wireless device that has no associated netdev. The crash occurs because the code passes a NULL wdev->netdev to rdev_get_radio_mask().
What conditions are required to trigger the issue?
The affected path requires a netdev-less wireless device and execution of cfg80211_calculate_bi_data(). Beaconing interfaces are not the triggering case, because their wdev->netdev is always valid.
What is the practical impact?
The described result is a kernel crash in mac80211, which can cause denial of service on the affected system.