Sceawere
Vulnerability Detail
CVE-2026-98339UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Kernel cfg80211 BSS Collision
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't filter by BSS type when removing stale entries When an assoc AP switches to a channel that already has a BSS entry, cfg80211_update_assoc_bss_entry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree. The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211_rehash_bss() then ran into it: WARN_ON(!cmp) Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T09:18:26.560Z",
"pubdate": "2026-10-06T09:18:26.560Z",
"executiveSummary": "This vulnerability involves an improper filtering logic in the Linux kernel cfg80211 subsystem during BSS (Basic Service Set) entry management.\nThe flaw allows for a BSS rbtree collision when an associated Access Point (AP) changes channels, potentially triggering a kernel warning condition.\nThe vulnerability type is an Improper Input Validation or Logic Error within the wireless configuration subsystem.\nAn attacker, such as a rogue AP or malicious device, can potentially trigger this condition by manipulating BSS capability advertisements.\nThe primary risk is a denial-of-service (DoS) condition via kernel kernel stack trace or warning assertion failure, which may lead to system instability or service disruption in the networking stack.\nExploitation requires the attacker to be in range and capable of influencing wireless scan results or connection updates perceived by the target device.",
"technicalDetails": "The root cause of the vulnerability lies within the cfg80211_update_assoc_bss_entry() function. When an associated AP migrates to a channel already occupied by an existing BSS entry, the kernel must remove the stale entry from the BSS rbtree to prevent collisions before rehashing the current, valid entry.\nPreviously, the lookup logic for identifying the stale entry enforced a strict BSS type match. If an existing BSS entry had different capability bits (e.g., an IBSS/Ad-hoc flag) compared to the current association, the lookup failed to match the stale entry. Consequently, the stale entry remained in the rbtree.\nWhen cfg80211_rehash_bss() is subsequently invoked, it attempts to insert the updated BSS information. Because the stale, mismatched entry was not removed, the insertion logic encounters a collision in the rbtree, resulting in a WARN_ON(!cmp) trigger within the kernel.\nA malicious actor can exploit this by acting as a rogue AP or broadcasting spoofed management frames that advertise conflicting BSS types (e.g., transitioning from Infrastructure mode to IBSS mode) on a channel being targeted by the victim's association update.\nThe attack flow follows these steps: 1) The target device associates with a legitimate AP. 2) The attacker broadcasts malformed or conflicting BSS information to populate the target's BSS scan cache with a stale, mismatching entry. 3) The target device performs an association update (e.g., channel switch). 4) The kernel attempts to update the BSS entry; due to the flawed filter, it fails to purge the stale entry. 5) The rehash operation triggers the kernel warning/assertion due to the rbtree collision. 6) Repeated exploitation of this condition can lead to persistent kernel warnings or potential crashes in high-traffic wireless environments.\nThis issue affects the Linux kernel cfg80211 wireless subsystem. It does not strictly require high-level privileges on the target system itself, as the trigger is network-based; however, the impact is localized to the wireless stack and kernel stability."
}