Skip to main content
Vulnerability Database/CVE-2026-98325

CVE-2026-98325: Linux Kernel mac80211 Memory Leak Vulnerability

CVE-2026-98325 is a memory management flaw in the Linux kernel mac80211 WiFi driver that causes failed TX packets to leak memory and not be reported to userspace. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-98325 Overview

CVE-2026-98325 affects the Linux kernel mac80211 wireless subsystem. The flaw resides in the transmit (TX) path, where socket buffer control block (skb->cb[]) metadata was not initialised early enough during frame construction. When header build or SKB resize operations failed, the kernel released the SKB without routing it through ieee80211_free_txskb(), preventing proper acknowledgement status reporting to userspace. The upstream fix restructures the failure paths so that TX info is set up before any error branch can be taken.

Critical Impact

Failed wireless transmissions were not reported back to userspace, breaking acknowledgement status delivery and leaving the mac80211 TX error paths inconsistent across kernel versions prior to the fix.

Affected Products

  • Linux kernel mac80211 wireless subsystem
  • Stable kernel trees receiving backports referenced in commits 03d67414, 0fb37d2b, 36e6f0a5, 420fcc2f, 50d3d79d, and df711e9f
  • Wireless drivers that rely on ieee80211_build_hdr() and ieee80211_skb_resize() for TX handling

Discovery Timeline

  • 2026-10-06 - CVE CVE-2026-98325 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-98325

Vulnerability Analysis

The issue sits in the mac80211 TX path. A prior commit, 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure"), closed a memory leak when ieee80211_build_hdr() failed, but it left the error handling fragmented. The failing SKB was not propagated through the standard ieee80211_free_txskb() helper, so userspace consumers that depend on TX acknowledgement reporting never learned that a frame had been dropped.

The resolution initialises skb->cb[] earlier in the transmit routine. Earlier initialisation makes the SKB safe to pass to ieee80211_free_txskb(), which both frees the buffer and emits the correct status notification. The patch also unifies the ieee80211_skb_resize() failure path with the header-build failure path, removing a class of silent frame drops in the wireless stack.

Root Cause

The root cause is incomplete initialisation of the TX control block before failure branches executed. Without the control block populated, the kernel could not call the standard free-with-status helper and defaulted to a plain kfree_skb() style release. This is a logic and lifecycle bug in the TX frame construction sequence rather than a memory-safety primitive.

Attack Vector

No remote exploitation vector has been published for this flaw. The impact is limited to incorrect status reporting and inconsistent error handling in the wireless TX path. The vulnerability is classified as a kernel reliability and correctness issue affecting local wireless operations rather than a direct code-execution primitive. Refer to the upstream commits for exact code-level behaviour: Linux Kernel Commit df711e9 and Linux Kernel Commit 420fcc2.

Detection Methods for CVE-2026-98325

Indicators of Compromise

  • No specific indicators of compromise have been published. The flaw manifests as missing TX acknowledgement status reports, not as attacker-controlled artifacts.
  • Kernel log entries related to ieee80211_build_hdr or ieee80211_skb_resize failures on unpatched kernels may indicate exposure to the buggy code path.

Detection Strategies

  • Inventory running kernel versions across Linux endpoints and servers and compare against the fixed stable releases referenced in the upstream commits.
  • Audit wireless driver stacks that depend on mac80211 to confirm they are built against a patched kernel tree.
  • Correlate reports of silent wireless frame drops or missing TX status callbacks with kernel build metadata.

Monitoring Recommendations

  • Monitor kernel package update channels for distribution advisories referencing the mac80211 TX info fix.
  • Track dmesg and journalctl -k output for anomalous wireless subsystem warnings during high TX failure rates.
  • Centralise kernel version telemetry so patch coverage can be verified across the fleet.

How to Mitigate CVE-2026-98325

Immediate Actions Required

  • Upgrade affected systems to a Linux stable kernel release that contains one of the fix commits listed in the NVD references.
  • Prioritise systems that rely on wireless connectivity for operational workloads, including laptops, mobile endpoints, and wireless access gateways.
  • Validate that distribution-provided kernel packages include the backport before closing remediation tickets.

Patch Information

The fix is distributed across multiple stable branches. Reference commits include Linux Kernel Commit 03d6741, Linux Kernel Commit 0fb37d2, Linux Kernel Commit 36e6f0a, Linux Kernel Commit 420fcc2, Linux Kernel Commit 50d3d79, and Linux Kernel Commit df711e9. Apply the kernel update supplied by your Linux distribution vendor.

Workarounds

  • No sanctioned workaround exists. Applying a patched kernel is the correct remediation.
  • On systems where immediate patching is not possible, limit reliance on userspace TX acknowledgement status for safety-critical workflows until the fix is deployed.
bash
# Verify running kernel version and compare against patched builds
uname -r

# Example: upgrade kernel on Debian-based systems
sudo apt update && sudo apt install --only-upgrade linux-image-$(uname -r | cut -d- -f3-)

# Example: upgrade kernel on RHEL-based systems
sudo dnf update kernel

# Reboot into the patched kernel
sudo systemctl reboot

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.