Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98339— wifi: cfg80211: don't filter by BSS type when removing stale entries

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: wifi: cfg80211: 在删除陈旧条目时,不要按 BSS 类型进行过滤 当一个已关联的接入点(AP)切换到一个已有 BSS 条目的信道时, 会先删除该旧条目,然后再重新哈希(rehash)新的真实条目,否则两者会在 BSS 红黑树(rbtree)中发生冲突。 此前,查找该条目还要求其 BSS 类型必须与连接所记录的 BSS 类型匹配。因此,如果一个条目 advertise( advertise 表示广播/通告)了例如 IBSS 能力位,则该条目会被保留在树中;随

CVSS 8.8 · High EPSS 0.29% · P19

Possible ATT&CK Techniques 2 AI

T1040.003 T1071.004 · DNS

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 6ef87a853327434ae1cd9c5a2c27a557fb4047fc affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 1380ee3a202dbb9f8e8b3c3b87eb410450d57799 affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< fb445ec7480da5d2b82bf681e3b4313603722729 affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 65fdb973bd905bc3f5cb045a04c1828f2d2a7e24 affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 64e23a36d8f04811372365b44cfca325f8e0f4bb affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 6d2fd26185678038ef2ea11dd4d2e6eccbf2dd25 affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< 0aa44982125c86b47961be5ac1c82eddab8080f3 affected
0afd425b1b64251f19b5d8d8b49bf56fefbc643f< b377e1000d963e7182a987082b4b06580bd7ac84 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98339

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: cfg80211: don't filter by BSS type when removing stale entries
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't filter by BSS type when removing stale entries When an assoc AP switches to a channel that already has a BSS entry, cfg80211_update_assoc_bss_entry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree. The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211_rehash_bss() then ran into it: WARN_ON(!cmp) Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0afd425b1b64251f19b5d8d8b49bf56fefbc643f ~ 6ef87a853327434ae1cd9c5a2c27a557fb4047fc -
Linux Linux 5.4 -

II. Public POCs for CVE-2026-98339

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98339

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98339 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98339

No comments yet


Leave a comment