Skip to main content
Vulnerability Database/CVE-2026-98327

CVE-2026-98327: Linux Kernel Mesh CSA Information Leak

CVE-2026-98327 is an information disclosure flaw in Linux kernel mesh networking that causes memory and state leaks during channel switch operations. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-98327 Overview

CVE-2026-98327 is a memory leak vulnerability in the Linux kernel's mac80211 wireless subsystem. The flaw affects mesh networking code that handles Channel Switch Announcement (CSA) operations. The ifmsh->csa structure is allocated in ieee80211_mesh_csa_beacon() and only freed when the channel switch completes in ieee80211_mesh_finish_csa(). Leaving the mesh network while a channel switch remains pending leaks the allocated memory. The ifmsh->csa_role and ifmsh->chsw_ttl state fields also persist across sessions, which can cause state confusion on subsequent operations. The upstream fix refactors the reset routine and invokes it from ieee80211_stop_mesh().

Critical Impact

Repeated mesh join and leave cycles during pending channel switches leak kernel memory and leave stale CSA state that can affect later wireless operations.

Affected Products

  • Linux kernel mac80211 subsystem (mesh mode)
  • Distributions shipping affected stable kernel branches prior to the referenced fix commits
  • Wireless drivers and devices operating in IEEE 802.11s mesh configurations

Discovery Timeline

  • 2026-10-06 - CVE-2026-98327 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-98327

Vulnerability Analysis

The vulnerability resides in the IEEE 802.11s mesh implementation inside the Linux kernel's mac80211 layer. The CSA mechanism allows a mesh node to coordinate a change of operating channel across peers. When a node initiates or participates in a CSA, ieee80211_mesh_csa_beacon() allocates the ifmsh->csa tracking structure. The allocation is paired with a release call inside ieee80211_mesh_finish_csa(), which only runs when the channel switch completes successfully.

If userspace or the driver tears down the mesh interface while a switch is still in flight, the completion path never executes. The allocation remains attached to the mesh interface context, producing a kernel memory leak each time the sequence repeats. Related CSA state variables, including csa_role and chsw_ttl, retain their prior values. A later rejoin can therefore observe inconsistent CSA state, leading to incorrect role handling or TTL accounting on the next channel switch attempt.

Root Cause

The root cause is incomplete resource cleanup in the mesh teardown path. ieee80211_stop_mesh() did not reset CSA-related fields, so lifetime of ifmsh->csa was tied solely to switch completion rather than interface lifetime. See the kernel commits for the patch content.

Attack Vector

Triggering the leak requires the ability to control mesh interface state while a CSA is pending. A local user with the privileges needed to configure wireless interfaces, or a crafted scripted sequence that joins and leaves a mesh during active channel switches, can repeatedly exhaust kernel memory. No remote network attacker interaction has been documented in the advisory.

See the kernel commits 860134b, aba8dfb, ba5bf83a, and bd3b211 for the applied fixes.

Detection Methods for CVE-2026-98327

Indicators of Compromise

  • Growth in kmalloc slab usage attributable to mac80211 after repeated mesh join and leave operations
  • Unexpected CSA state carried across mesh sessions on the same interface, including stale csa_role or chsw_ttl values
  • Kernel warnings or driver logs referencing incomplete channel switch state during mesh teardown

Detection Strategies

  • Compare running kernel version against the patched commits in linux-stable and flag hosts on unpatched trees
  • Monitor /proc/slabinfo and /proc/meminfo on systems that use mesh wireless networking for sustained unaccounted growth
  • Audit systems configured for IEEE 802.11s mesh operation and prioritize them for patch validation

Monitoring Recommendations

  • Enable kernel memory leak detection tools such as kmemleak on test systems to confirm leak absence after patching
  • Collect dmesg output for mesh-related warnings during interface stop operations
  • Track wireless configuration changes through endpoint telemetry to correlate mesh teardown events with memory anomalies

How to Mitigate CVE-2026-98327

Immediate Actions Required

  • Apply the upstream kernel patches referenced in the stable commits and rebuild or update affected kernels
  • Inventory systems running mac80211 in mesh mode and schedule reboots after patch deployment
  • Restrict wireless configuration privileges to trusted administrators to limit local trigger paths

Patch Information

The fix is distributed across the following linux-stable commits: 860134b, aba8dfb, ba5bf83a, and bd3b211. The patches extract CSA reset logic into a helper and invoke it from ieee80211_stop_mesh() to free ifmsh->csa and clear related state.

Workarounds

  • Disable IEEE 802.11s mesh mode on affected systems until the kernel is patched
  • Avoid tearing down mesh interfaces while a channel switch is pending by waiting for CSA completion before issuing stop commands
  • Reboot systems periodically if mesh usage is required before patches can be applied, to reclaim leaked kernel memory

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.