CVE-2026-98325 PUBLISHED

wifi: mac80211: set up the TX info early to fix failure paths

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: set up the TX info early to fix failure paths

The previous commit 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure") cleaned up the leak, but still left the code a bit messy and the failed SKB didn't get reported to userspace.

Fix this up by initialising skb->cb[] earlier, which allows using ieee80211_free_txskb() and therefore reports it for the failure in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize() failure path with it.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to df711e9fa20d7e996711c7f43a11a71805bef78d (excl.)
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to 420fcc2fdeae6ecd682d2b1605a0a54c88aed4aa (excl.)
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to 36e6f0a5e6d7238f4023e77f423c1c1414374309 (excl.)
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to 0fb37d2b6cb829cebdaea80f39011469f474bdcc (excl.)
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to 03d67414bd05b86029afc14535238a9393eac1c6 (excl.)
  • affected from c3e7724b6bc2f25e46c38dbe68f09d71fafeafb8 to 50d3d79dc0743b616afb00d01a626c76758721f7 (excl.)
  • Version fd39be7ff6f81f2dc91ba6e5f87944abef5b4802 is affected
  • affected from 3.6.3 to 3.7 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.7 is affected
  • unaffected from 0 to 3.7 (excl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References