CVE-2026-98329

Summary

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't allow injecting frames wider than the chanctx

Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.

If the bandwidth requested is too wide, that triggers a warning in hwsim:

WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))

Drop such frames entirely instead since they cannot be sent.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux646e76bb5daf4ca38438c69ffb72cccb605f3466 < a5c715eda066cba5ce3372759188ba8636dca629affected
LinuxLinux646e76bb5daf4ca38438c69ffb72cccb605f3466 < 73f48f7e16cadfc74f444ccd10c1d3ae253e2e27affected
LinuxLinux646e76bb5daf4ca38438c69ffb72cccb605f3466 < c69718519a81e87284494d0c6e6eb7bdd834707aaffected
LinuxLinux646e76bb5daf4ca38438c69ffb72cccb605f3466 < e14bf37bb2b3853012ff160131d1c6233f7a9cc9affected
LinuxLinux4.7affected
LinuxLinux0 < 4.7unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References