CVE-2026-98336 Overview
CVE-2026-98336 affects the Linux kernel mac80211 wireless subsystem. The flaw stems from improper handling of Traffic Control (TC) setup offload on AP_VLAN interfaces. These interfaces are purely virtual constructs within mac80211 and have no corresponding hardware driver context. Attempting to offload TC setup for them to drivers produces undefined behavior because the underlying AP interface may be unknown or change over time.
The fix rejects TC offload for AP_VLAN interfaces, forcing the operation to be handled in software instead. The vulnerability was resolved through multiple backported commits across supported stable kernel branches.
Critical Impact
Improper TC offload handling on virtual AP_VLAN interfaces can lead to kernel-level instability in wireless access point deployments relying on VLAN segmentation.
Affected Products
- Linux kernel mac80211 wireless subsystem
- Systems configured with AP_VLAN interfaces for wireless access point VLAN segmentation
- Wireless drivers supporting TC offload callbacks via mac80211
Discovery Timeline
- 2026-10-06 - CVE-2026-98336 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-98336
Vulnerability Analysis
The Linux mac80211 subsystem supports Traffic Control (TC) offload, allowing hardware drivers to accelerate packet classification and filtering. When a TC setup request arrives for a wireless interface, mac80211 forwards the request to the underlying driver.
The vulnerability arises when the target interface type is AP_VLAN. An AP_VLAN interface is a virtual construct that groups stations under a parent Access Point (AP) interface. It has no direct hardware representation. Forwarding TC offload callbacks for such an interface produces inconsistent state because the AP interface context may not be known at offload time and may change during the lifetime of the VLAN.
Root Cause
The root cause is a missing interface-type check in the mac80211 TC offload path. The subsystem accepted TC setup offload requests regardless of whether the originating netdev was a physical-backed interface or a virtual AP_VLAN. Drivers invoked for the virtual case operated on invalid or ambiguous interface state.
Attack Vector
The attack vector requires local privileged access to configure wireless interfaces and issue TC commands against an AP_VLAN netdev. No remote network vector is documented. Exploitation potential is limited to misconfiguration-driven kernel instability rather than remote code execution. The upstream commit series rejects the offload request so that TC rules are applied in software.
See the upstream fixes for implementation detail: Linux Kernel Commit 362bd5b, Commit 40bc8a2, Commit 790221e, Commit 9c34f01, and Commit ea3ef21.
Detection Methods for CVE-2026-98336
Indicators of Compromise
- Kernel log entries referencing mac80211 TC setup failures or warnings on AP_VLAN netdev operations
- Unexpected driver callbacks or kernel oops traces originating from the TC offload path on wireless interfaces
- Presence of AP_VLAN interfaces with active TC filter rules on unpatched kernels
Detection Strategies
- Inventory running kernel versions and compare against the fixed stable branches listed in the upstream commits
- Audit wireless host configurations for AP_VLAN interface usage combined with tc filter rules
- Monitor dmesg output for warnings generated by the mac80211 offload rejection path after patch application
Monitoring Recommendations
- Collect kernel ring buffer logs centrally and alert on new mac80211 warnings referencing ieee80211_setup_tc
- Track netlink events for TC configuration changes on wireless netdevs across access point hosts
- Correlate wireless driver versions with kernel patch levels through configuration management tooling
How to Mitigate CVE-2026-98336
Immediate Actions Required
- Apply the stable kernel updates containing the referenced upstream commits to all affected Linux hosts
- Reboot patched systems to activate the corrected mac80211 module
- Validate that TC rules on AP_VLAN interfaces continue to function in software after patching
Patch Information
The fix is distributed across five stable branch backports: 362bd5b, 40bc8a2, 790221e, 9c34f01, and ea3ef21. Each commit modifies mac80211 to reject TC setup offload when the interface type is NL80211_IFTYPE_AP_VLAN, ensuring the operation falls back to software processing. Consult your Linux distribution advisory for the specific kernel package version that includes these backports.
Workarounds
- Avoid applying tc filter rules directly to AP_VLAN interfaces until the kernel patch is installed
- Apply TC rules to the parent AP interface instead of its VLAN children where functionally equivalent
- Restrict local privileged access on wireless access point hosts to limit who can configure TC offload
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.