Skip to main content
Vulnerability Database/CVE-2026-98339

CVE-2026-98339: Linux Kernel Wi-Fi Privilege Escalation

CVE-2026-98339 is a privilege escalation vulnerability in the Linux kernel Wi-Fi cfg80211 subsystem that can be exploited by rogue access points. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-98339 Overview

CVE-2026-98339 is a Linux kernel vulnerability in the cfg80211 wireless subsystem. The flaw affects cfg80211_update_assoc_bss_entry(), which incorrectly filters by Basic Service Set (BSS) type when removing stale entries from the BSS red-black tree. When an associated access point switches to a channel that already contains a BSS entry advertising a different capability (for example, Independent BSS), the stale entry is left in place. A subsequent call to cfg80211_rehash_bss() then triggers a WARN_ON(!cmp) kernel warning. The condition can be reached by a rogue access point or wireless device within radio range.

Critical Impact

An adjacent-network attacker can trigger kernel warnings and potential instability in the Linux wireless stack by advertising mismatched BSS capability bits for a channel in use by an associated AP.

Affected Products

  • Linux kernel cfg80211 wireless configuration subsystem
  • Multiple stable kernel branches referenced by commits 0aa44982, 1380ee3a, 64e23a36, 65fdb973, 6d2fd261, 6ef87a85, b377e100, and fb445ec7
  • Any distribution shipping affected kernels with Wi-Fi (STA mode) enabled

Discovery Timeline

  • 2026-10-06 - CVE-2026-98339 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98339

Vulnerability Analysis

The Linux kernel maintains discovered wireless networks in a red-black tree keyed by BSSID, channel, and related attributes. When a station's associated AP moves to a channel where a prior scan already recorded a BSS entry, cfg80211_update_assoc_bss_entry() must evict the colliding entry before rehashing the live association. The lookup used to find the stale entry additionally required a matching BSS type (infrastructure vs. Independent BSS). This additional filter allowed entries advertising incompatible capability bits to remain in the tree, which then collided with the rehashed association and tripped a WARN_ON(!cmp) inside cfg80211_rehash_bss().

Root Cause

The root cause is an overly strict lookup predicate in the stale-entry removal path. The code assumed BSS type would not change for a given BSSID on a given channel, but a rogue or misbehaving device can advertise mismatched capability bits. The fix drops the type check so any entry matching the BSSID and channel comparison is removed before rehashing [CWE category: improper input validation leading to kernel assertion].

Attack Vector

Exploitation requires adjacent-network access. An attacker broadcasts beacon or probe-response frames crafted to populate the BSS cache with an entry advertising a capability bit (such as IBSS) for a channel the victim's associated AP later moves to. When the AP performs a channel switch, the stale entry remains in the rbtree and triggers the kernel warning on the next rehash. Repeated triggering can produce log flooding and may expose further latent bugs in the wireless stack.

No verified public exploit code is available. See the upstream fix in the referenced kernel commits for full technical context: Kernel Commit 0aa44982 and Kernel Commit 1380ee3a.

Detection Methods for CVE-2026-98339

Indicators of Compromise

  • Kernel log entries containing WARN_ON traces originating in cfg80211_rehash_bss or cfg80211_update_assoc_bss_entry
  • Unexpected beacon frames in the vicinity advertising IBSS capability for channels already occupied by infrastructure APs
  • Repeated channel-switch announcements from associated APs correlated with wireless subsystem warnings

Detection Strategies

  • Monitor dmesg and /var/log/kern.log for warnings referencing cfg80211 BSS rehashing or rbtree collisions
  • Correlate kernel warnings with iw event output showing channel-switch (CSA) activity on the associated interface
  • Use wireless intrusion detection to flag beacons that advertise conflicting capability bits for the same BSSID across scans

Monitoring Recommendations

  • Forward kernel ring-buffer events from Linux endpoints and Wi-Fi gateways to a central logging platform for pattern analysis
  • Alert on recurring WARN_ON conditions in the wireless subsystem, which indicate either this bug or related memory-tree inconsistencies
  • Track EPSS trend data for CVE-2026-98339 (currently 0.285%, percentile 19.256) to adjust prioritization as exploitation signal changes

How to Mitigate CVE-2026-98339

Immediate Actions Required

  • Apply the upstream Linux kernel patches referenced in the NVD entry to all affected stable branches
  • Rebuild and reboot Linux systems that act as Wi-Fi stations, including laptops, embedded devices, and IoT gateways
  • Where patching is delayed, restrict wireless clients to trusted RF environments and disable auto-association with open or unknown SSIDs

Patch Information

Upstream fixes are available in the following stable kernel commits: 0aa44982, 1380ee3a, 64e23a36, 65fdb973, 6d2fd261, 6ef87a85, b377e100, and fb445ec7. Install the distribution-provided kernel update that incorporates these commits.

Workarounds

  • Disable Wi-Fi on affected Linux systems that do not require wireless connectivity until the kernel is patched
  • Operate in RF-controlled environments and avoid associating with APs in uncontrolled public spaces
  • Enforce 802.1X or WPA3-Enterprise authentication to reduce exposure to rogue AP beacons that would otherwise populate the BSS cache

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.