CVE-2026-98346 PUBLISHED

wifi: cfg80211: don't get the radio mask for netdev-less wdevs

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: don't get the radio mask for netdev-less wdevs

cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with wdev->netdev, which can be NULL and then crashes in mac80211.

To avoid that, invert the order of checks since wdev->netdev is always valid for beaconing interfaces.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from abb4cfe3661aa05426916b21164f88ca5a405a3a to 5b313159c970e945ee125ca87fad0d96ed913e55 (excl.)
  • affected from abb4cfe3661aa05426916b21164f88ca5a405a3a to 693d777846d525b8b218bad97a1befa5d9bd4334 (excl.)
  • affected from abb4cfe3661aa05426916b21164f88ca5a405a3a to 7166da84a7fe3553f9065782fd80299a37b150e5 (excl.)
  • affected from abb4cfe3661aa05426916b21164f88ca5a405a3a to a7783e585360ee05dfe21d3173dbbe985c94f29e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.11 is affected
  • unaffected from 0 to 6.11 (excl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References