---
id: CVE-2026-98327
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mac80211: mesh: reset the CSA state when leaving

  ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
  in ieee80211_mesh_finish_csa(), i.e
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mac80211: mesh: reset the CSA state when leaving

  ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
  in ieee80211_mesh_finish_csa(), i.e. when …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b8456a14e9d2770846fcf74de18ff95b676149a3 <
    aba8dfb45864441199748c33ce3c1c8ca121c8bd
  - >-
    Linux >= b8456a14e9d2770846fcf74de18ff95b676149a3 <
    bd3b21145ae2e781daac1bbd19216a63ab4e0cbd
  - >-
    Linux >= b8456a14e9d2770846fcf74de18ff95b676149a3 <
    ba5bf83a81e8832cb84bb3a2da67512f81f57a02
  - >-
    Linux >= b8456a14e9d2770846fcf74de18ff95b676149a3 <
    860134b3af77970e006feab7e5decb8c84771c7f
  - Linux 3.13
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:24.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98327'
references:
  - url: 'https://git.kernel.org/stable/c/860134b3af77970e006feab7e5decb8c84771c7f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aba8dfb45864441199748c33ce3c1c8ca121c8bd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ba5bf83a81e8832cb84bb3a2da67512f81f57a02'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bd3b21145ae2e781daac1bbd19216a63ab4e0cbd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.405Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: reset the CSA state when leaving

ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.
Leaving the mesh while a switch is still pending therefore leaks it.

Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak
in this case, so things can get mixed up in addition to the memory
leak.

Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
