Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98325— wifi: mac80211: set up the TX info early to fix failure paths

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: wifi: mac80211:尽早设置 TX 信息以修复失败路径 前一个提交 2c51457d930f(“wifi: mac80211:在 TX 头部构建失败时释放 ACK 状态帧”)清除了泄漏问题,但代码仍然有些杂乱,并且失败的 SKB 未向用户空间报告。 通过尽早初始化 skb->cb[] 来解决此问题,从而可以使用 ieee80211_free_txskb() 函数,这样在 ieee80211_build_hdr() 中出现失败时也能正确报告,并将 ieee80211

AI Predicted 5.0 Difficulty: Trivial EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< df711e9fa20d7e996711c7f43a11a71805bef78d affected
c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< 420fcc2fdeae6ecd682d2b1605a0a54c88aed4aa affected
c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< 36e6f0a5e6d7238f4023e77f423c1c1414374309 affected
c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< 0fb37d2b6cb829cebdaea80f39011469f474bdcc affected
c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< 03d67414bd05b86029afc14535238a9393eac1c6 affected
c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8< 50d3d79dc0743b616afb00d01a626c76758721f7 affected
fd39be7ff6f81f2dc91ba6e5f87944abef5b4802 affected
3.6.3< 3.7 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98325

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: mac80211: set up the TX info early to fix failure paths
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: set up the TX info early to fix failure paths The previous commit 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure") cleaned up the leak, but still left the code a bit messy and the failed SKB didn't get reported to userspace. Fix this up by initialising skb->cb[] earlier, which allows using ieee80211_free_txskb() and therefore reports it for the failure in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize() failure path with it.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 ~ df711e9fa20d7e996711c7f43a11a71805bef78d -
Linux Linux 3.7 -

II. Public POCs for CVE-2026-98325

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98325

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98325 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98325

No comments yet


Leave a comment