CVE-2026-98326 Overview
CVE-2026-98326 is a Linux kernel vulnerability in the mac80211 wireless subsystem. The flaw affects the mesh networking code path, where ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(). When the start operation fails, the channel context is not released. During subsequent interface removal, the kernel attempts to unassign the channel context after it has already been removed from the driver, triggering a WARNING in drv_unassign_vif_chanctx. The resolved patch ensures the channel is correctly released when mesh start fails.
Critical Impact
A failed mesh start operation leaves kernel state inconsistent, causing a warning and potential resource mismanagement during interface teardown in mac80211-based Wi-Fi mesh deployments.
Affected Products
- Linux kernel mac80211 subsystem (mesh code path)
- Wireless drivers using mac80211 with mesh mode enabled
- mac80211_hwsim simulation module as reproducer
Discovery Timeline
- 2026-10-06 - CVE CVE-2026-98326 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-98326
Vulnerability Analysis
The defect resides in the mesh join sequence of the Linux kernel mac80211 layer. ieee80211_join_mesh() first acquires a channel context for the virtual interface. It then invokes ieee80211_start_mesh(), which may return an error. The original code did not release the previously acquired channel context on this failure path. The virtual interface therefore retained a reference to a channel context that was never fully bound to the driver.
When userspace later removed the interface, ieee80211_teardown_sdata() invoked ieee80211_link_release_channel(), which eventually called drv_unassign_vif_chanctx(). The driver-side state had already been torn down, so the check-sdata-in-driver assertion fired and emitted a WARNING from net/mac80211/driver-ops.c:366.
Root Cause
The root cause is missing error-path cleanup in ieee80211_join_mesh(). The channel context acquired before the call to ieee80211_start_mesh() was not released when the start routine failed. This is a resource management flaw producing inconsistent state between mac80211 and the underlying driver.
Attack Vector
Triggering the condition requires the ability to initiate a mesh join operation that fails during ieee80211_start_mesh(). This generally requires local privileges to configure wireless interfaces. The observed consequence is a kernel warning and leaked channel context state during interface removal. No evidence of remote exploitation or memory corruption is reported in the advisory.
Technical details and the applied patches are available in the referenced kernel commits, including Kernel Commit 41bee71 and Kernel Commit f0afcec.
Detection Methods for CVE-2026-98326
Indicators of Compromise
- Kernel log entries containing Failed check-sdata-in-driver check, flags: 0x0 for a wireless interface.
- WARNING traces originating from net/mac80211/driver-ops.c referencing drv_unassign_vif_chanctx and ieee80211_link_release_channel.
- Repeated mesh join failures followed by interface removal events in dmesg.
Detection Strategies
- Monitor kernel ring buffer output for mac80211 warnings tied to mesh interface teardown.
- Correlate cfg80211 interface lifecycle events with subsequent warning traces to identify affected hosts.
- Track kernel versions deployed across Linux fleets and flag systems running unpatched mac80211 builds with mesh functionality enabled.
Monitoring Recommendations
- Forward dmesg and /var/log/kern.log entries to a centralized logging platform and alert on mac80211 WARN splats.
- Inventory hosts that load mesh-capable Wi-Fi drivers or mac80211_hwsim and prioritize them for patch validation.
- Review wireless configuration changes made by non-administrative users to detect unexpected mesh join attempts.
How to Mitigate CVE-2026-98326
Immediate Actions Required
- Apply the upstream kernel patches referenced in the stable tree commits for CVE-2026-98326.
- Rebuild or update distribution kernels to a version incorporating the mac80211 mesh fix.
- Restart affected systems after patching to ensure the new mac80211 module is loaded.
Patch Information
The fix is distributed across multiple stable kernel branches. Relevant commits include Kernel Commit 41bee71, Kernel Commit 4a4e3fa, Kernel Commit 632f7ac, Kernel Commit ae97fff, Kernel Commit b51f5a3, and Kernel Commit f0afcec. The patches add explicit channel release handling when ieee80211_start_mesh() returns an error inside ieee80211_join_mesh().
Workarounds
- Disable mesh mode on wireless interfaces where it is not required.
- Avoid loading mac80211_hwsim on production systems unless needed for testing.
- Restrict CAP_NET_ADMIN to trusted administrators to limit who can trigger mesh join operations.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.