CVE-2026-98326 PUBLISHED

wifi: mac80211: mesh: release the channel if start fails

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: release the channel if start fails

ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting:

wlan0: Failed check-sdata-in-driver check, flags: 0x0 WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx ieee80211_assign_link_chanctx __ieee80211_link_release_channel ieee80211_link_release_channel ieee80211_teardown_sdata unregister_netdevice_many_notify _cfg80211_unregister_wdev ieee80211_remove_interfaces ieee80211_unregister_hw mac80211_hwsim_del_radio hwsim_exit_net

Correctly release the channel on start failures.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to f0afcec2129c166e61821d6ae097061155f01b12 (excl.)
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to b51f5a310bd6888b90bb9546a8081215dcfe6fbe (excl.)
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to 632f7acfe6dac1278a9314eaaab14fada400ddaf (excl.)
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to 41bee71112db53651ba9a9030de1b843255a4a7f (excl.)
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to 4a4e3fa77ea36d3419d806fb5883ef425a605a5d (excl.)
  • affected from 2b5e19677592c167d012c2d129407f39d2bdeb8d to ae97fff6495a8764bc0ef281cfe5444f701e527f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.9 is affected
  • unaffected from 0 to 3.9 (excl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References