CVE-2026-98329 PUBLISHED

wifi: mac80211: don't allow injecting frames wider than the chanctx

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't allow injecting frames wider than the chanctx

Frames injected on a monitor interface can carry a radiotap field requesting a bandwidth, which mac80211 passes down to the driver regardless of the the actual operational bandwidth.

If the bandwidth requested is too wide, that triggers a warning in hwsim:

WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))

Drop such frames entirely instead since they cannot be sent.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 646e76bb5daf4ca38438c69ffb72cccb605f3466 to a5c715eda066cba5ce3372759188ba8636dca629 (excl.)
  • affected from 646e76bb5daf4ca38438c69ffb72cccb605f3466 to 73f48f7e16cadfc74f444ccd10c1d3ae253e2e27 (excl.)
  • affected from 646e76bb5daf4ca38438c69ffb72cccb605f3466 to c69718519a81e87284494d0c6e6eb7bdd834707a (excl.)
  • affected from 646e76bb5daf4ca38438c69ffb72cccb605f3466 to e14bf37bb2b3853012ff160131d1c6233f7a9cc9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.7 is affected
  • unaffected from 0 to 4.7 (excl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References