CVE-2026-98329
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: don't allow injecting frames wider than the chanctx
Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.
If the bandwidth requested is too wide, that triggers a warning in hwsim:
WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))
Drop such frames entirely instead since they cannot be sent.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 646e76bb5daf4ca38438c69ffb72cccb605f3466 < a5c715eda066cba5ce3372759188ba8636dca629 | affected |
| Linux | Linux | 646e76bb5daf4ca38438c69ffb72cccb605f3466 < 73f48f7e16cadfc74f444ccd10c1d3ae253e2e27 | affected |
| Linux | Linux | 646e76bb5daf4ca38438c69ffb72cccb605f3466 < c69718519a81e87284494d0c6e6eb7bdd834707a | affected |
| Linux | Linux | 646e76bb5daf4ca38438c69ffb72cccb605f3466 < e14bf37bb2b3853012ff160131d1c6233f7a9cc9 | affected |
| Linux | Linux | 4.7 | affected |
| Linux | Linux | 0 < 4.7 | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/a5c715eda066cba5ce3372759188ba8636dca629
- https://git.kernel.org/stable/c/73f48f7e16cadfc74f444ccd10c1d3ae253e2e27
- https://git.kernel.org/stable/c/c69718519a81e87284494d0c6e6eb7bdd834707a
- https://git.kernel.org/stable/c/e14bf37bb2b3853012ff160131d1c6233f7a9cc9
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.