CVE-2026-98326

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: release the channel if start fails

ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting:

wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx ieee80211_assign_link_chanctx __ieee80211_link_release_channel ieee80211_link_release_channel ieee80211_teardown_sdata unregister_netdevice_many_notify _cfg80211_unregister_wdev ieee80211_remove_interfaces ieee80211_unregister_hw mac80211_hwsim_del_radio hwsim_exit_net

Correctly release the channel on start failures.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < f0afcec2129c166e61821d6ae097061155f01b12affected
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < b51f5a310bd6888b90bb9546a8081215dcfe6fbeaffected
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < 632f7acfe6dac1278a9314eaaab14fada400ddafaffected
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < 41bee71112db53651ba9a9030de1b843255a4a7faffected
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < 4a4e3fa77ea36d3419d806fb5883ef425a605a5daffected
LinuxLinux2b5e19677592c167d012c2d129407f39d2bdeb8d < ae97fff6495a8764bc0ef281cfe5444f701e527faffected
LinuxLinux3.9affected
LinuxLinux0 < 3.9unaffected
LinuxLinux6.1.189 <= 6.1.*unaffected
LinuxLinux6.6.158 <= 6.6.*unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References