{"id":"CVE-2026-98334","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: reset state when starting AP fails\n\nieee80211_start_ap() can set enable_beacon (and beacon_int) and fail\nlater, leaving it set forever","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: reset state when starting AP fails\n\nieee80211_start_ap() can set enable_beacon (and beacon_int) and fail\nlater, leaving it set forever. Scanning can the…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= d6a83228823fc0cc8d79d95c9f0bf568b7317862 < d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32","Linux >= d6a83228823fc0cc8d79d95c9f0bf568b7317862 < 5d5ff5b36f5748a2a077f875a73ccb26860d3fcc","Linux >= d6a83228823fc0cc8d79d95c9f0bf568b7317862 < 6eac225f59c1c2277ac74f8a716d6df0ba3b8d28","Linux >= d6a83228823fc0cc8d79d95c9f0bf568b7317862 < 3f28551d0241254a75626d868041c6340285088b","Linux 3.9"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:25.903","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98334","references":[{"url":"https://git.kernel.org/stable/c/3f28551d0241254a75626d868041c6340285088b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d5ff5b36f5748a2a077f875a73ccb26860d3fcc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6eac225f59c1c2277ac74f8a716d6df0ba3b8d28","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.402Z","slug":"CVE-2026-98334","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: reset state when starting AP fails\n\nieee80211_start_ap() can set enable_beacon (and beacon_int) and fail\nlater, leaving it set forever. Scanning can then attempt to restore\nbeaconing on such an interface, leading to:\n\n  Oops: divide error: 0000 [#1] SMP KASAN NOPTI\n  RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00\n  Call Trace:\n   drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160\n   __ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519\n   ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193\n   cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538\n\nin hwsim. Also, cfg80211 then allows changing the interface type,\nand the off-channel path getgs confused about beaconing as well,\nleading to another warning:\n\n  WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122\n   ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]\n   __ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882\n\nReset the state on failures to always have it correct.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}