CVE-2026-98340 Overview
CVE-2026-98340 is a Linux kernel vulnerability in the cfg80211 wireless configuration subsystem. The flaw resides in __cfg80211_bss_update() and the related cfg80211_combine_bsses() logic that handles hidden Basic Service Set (BSS) grouping during Wi-Fi scanning. When a probe response arrives for an unknown BSS, the code groups it with existing entries sharing the same BSSID and a hidden SSID without verifying that the matched entry contains beacon Information Elements (IEs). A later-arriving beacon with a hidden SSID triggers WARN_ON_ONCE() assertions in the kernel log because entries without beacon IEs are not expected to belong to a group.
Critical Impact
Malformed or sequenced Wi-Fi probe responses and beacons can trigger kernel warning conditions in the cfg80211 scan database, producing noisy stack traces and potential wireless scan state inconsistencies.
Affected Products
- Linux kernel cfg80211 subsystem (wireless scanning / BSS tracking)
- Multiple stable kernel branches referenced by the eight published fix commits
- Any distribution shipping an unpatched kernel with Wi-Fi (cfg80211) support
Discovery Timeline
- 2026-10-06 - CVE-2026-98340 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-98340
Vulnerability Analysis
The cfg80211 layer maintains a database of observed BSSes built from both beacon frames and probe responses. Hidden networks advertise a zero-length or NUL-filled SSID in beacons and expose the real SSID only in directed probe responses. To reconcile these views, __cfg80211_bss_update() searches for an existing hidden entry with the same BSSID and groups the new probe response with it, inheriting beacon IEs from the matched entry.
The defect is that the lookup does not require the matched entry to actually carry beacon IEs. Two probe-response-derived entries can therefore be grouped together even though neither has beacon elements. When a genuine beacon with a hidden SSID later arrives, cfg80211_combine_bsses() enumerates probe-response entries lacking beacon IEs and finds the two already linked together. This violates the invariant that unbeaconed entries are not members of a hidden-BSS group, firing WARN_ON_ONCE(bss->pub.hidden_beacon_bss) and WARN_ON_ONCE(!list_empty(&bss->hidden_list)).
Root Cause
The root cause is a missing precondition check in the hidden-BSS grouping path. The matching function treats any entry with the right BSSID and hidden SSID as a group anchor, regardless of whether it actually originated from a beacon frame. This is a logic error [CWE-logic] in state management, not a memory-safety bug.
Attack Vector
Triggering the condition requires a local wireless scan to observe a specific ordering of frames: probe responses from the same BSSID with hidden SSIDs, followed by a beacon with a hidden SSID. A nearby attacker operating a rogue access point can craft and transmit such frames deliberately. The resulting kernel warnings produce log noise, consume CPU in warning paths, and can be used to pollute the scan cache. See the referenced git commits for the exact code change and conditions.
Detection Methods for CVE-2026-98340
Indicators of Compromise
- Repeated WARN_ON_ONCE splats in dmesg referencing cfg80211_combine_bsses, hidden_beacon_bss, or hidden_list in the stack trace
- Unexpected growth or churn in the kernel scan cache visible through iw dev <iface> scan dump
- Presence of multiple nearby access points broadcasting the same BSSID with hidden SSIDs during scans
Detection Strategies
- Monitor kernel ring buffer and journald for warnings sourced from net/wireless/scan.c
- Correlate wireless telemetry with host-based logs to identify repeated rogue AP activity near endpoints
- Alert on sudden spikes in cfg80211 subsystem warnings across fleets of mobile endpoints
Monitoring Recommendations
- Forward /var/log/kern.log or journald kernel events to a central SIEM for pattern analysis
- Track kernel versions across the Linux fleet and flag hosts running unpatched branches
- Baseline wireless scan behavior for laptops to detect anomalous probe/beacon patterns
How to Mitigate CVE-2026-98340
Immediate Actions Required
- Apply the stable kernel updates containing the fix commits listed in the NVD references
- Prioritize mobile endpoints and systems that routinely roam across untrusted Wi-Fi environments
- Rebuild and redeploy any custom kernels or out-of-tree Wi-Fi drivers against patched sources
Patch Information
The fix constrains __cfg80211_bss_update() to only group entries when a beacon has already been received for the candidate anchor. Entries without beacon IEs remain separate and are combined later when a beacon arrives. The change is distributed across eight stable backports, including Kernel Git Commit 068843e, Kernel Git Commit 332ea15, Kernel Git Commit 3658093, Kernel Git Commit 4cd6a51, Kernel Git Commit 73365b8, Kernel Git Commit 7405dd1, Kernel Git Commit 74ed0d9, and Kernel Git Commit 86235be.
Workarounds
- Disable Wi-Fi on systems that do not require wireless connectivity until kernels are patched
- Avoid associating with or scanning in environments containing untrusted or suspicious access points
- Restrict wireless use to known SSIDs and consider disabling background scanning where feasible
# Verify running kernel and check whether the fix is present
uname -r
# Update the kernel package on common distributions
sudo apt update && sudo apt install --only-upgrade linux-image-$(uname -r) # Debian/Ubuntu
sudo dnf update kernel # RHEL/Fedora
# Reboot into the patched kernel
sudo systemctl reboot
# Temporary mitigation: unload the Wi-Fi stack on non-wireless hosts
sudo modprobe -r cfg80211
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.