-

CVE-2026-98340

wifi: cfg80211: only group hidden BSSes with beacon entries

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: only group hidden BSSes with beacon entries

When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.

But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there's a group without beacon elements.

If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its

  WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
  WARN_ON_ONCE(!list_empty(&bss->hidden_list))

which are there because an entry without beacon elements is not supposed
to be part of a group yet.

Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 4cd6a518ce7527284bbc9baab5fa2453a7d477c2
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 74ed0d992f392c75e1969415527e06df3f7a4034
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 3658093df69849daf4f813a8f087f358e13be203
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 73365b81630b57e1a1f9d50dc87281797855c2ac
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 7405dd19bda4537a2843637d8d7bed1efd4776cf
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 86235be788094131912e9bd8412b358d91d99f49
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 332ea1502c46f53375cb109fa82bfaff818f3a41
Status affected
Version 4593c4cbe1c96b3995727dc42f6aa103f4ff5afc
Version < 068843ed0902c552a13860c5ec6b2ca65b57a065
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.9
Status affected
Version 0
Version < 3.9
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.073
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4cd6a518ce7527284bbc9baab5fa2453a7d477c2
https://git.kernel.org/stable/c/74ed0d992f392c75e1969415527e06df3f7a4034
https://git.kernel.org/stable/c/3658093df69849daf4f813a8f087f358e13be203
https://git.kernel.org/stable/c/73365b81630b57e1a1f9d50dc87281797855c2ac
https://git.kernel.org/stable/c/7405dd19bda4537a2843637d8d7bed1efd4776cf
https://git.kernel.org/stable/c/86235be788094131912e9bd8412b358d91d99f49
https://git.kernel.org/stable/c/332ea1502c46f53375cb109fa82bfaff818f3a41
https://git.kernel.org/stable/c/068843ed0902c552a13860c5ec6b2ca65b57a065