---
id: CVE-2026-98337
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mac80211: don't start a ROC while scanning

  The ROC work can be pending when a scan starts (which requires
  ROC list to be empty, but that's possible), and then a …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: mac80211: don't start a ROC while scanning

  The ROC work can be pending when a scan starts (which requires
  ROC list to be empty, but that's possible), and then a …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= aaa016ccd5df89d73483d0d51ee1f692978ccc35 <
    5dc8ec2f8d1d62914661577c23ec151f5c9734a4
  - >-
    Linux >= aaa016ccd5df89d73483d0d51ee1f692978ccc35 <
    81baab8b645ec532bad2b7a8464191c720ef8fd9
  - >-
    Linux >= aaa016ccd5df89d73483d0d51ee1f692978ccc35 <
    58b806f699052c572dec6cab2c376f884f27e98f
  - >-
    Linux >= aaa016ccd5df89d73483d0d51ee1f692978ccc35 <
    733f0fde95392ed5f61a4e36aee661ea8d0e8581
  - Linux 4.5
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:26.303'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98337'
references:
  - url: 'https://git.kernel.org/stable/c/58b806f699052c572dec6cab2c376f884f27e98f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5dc8ec2f8d1d62914661577c23ec151f5c9734a4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/733f0fde95392ed5f61a4e36aee661ea8d0e8581'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/81baab8b645ec532bad2b7a8464191c720ef8fd9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.401Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: don't start a ROC while scanning

The ROC work can be pending when a scan starts (which requires
ROC list to be empty, but that's possible), and then a new ROC
can be added to the list and the work will pick it up.

Avoid starting that ROC if a scan made it between things, as
otherwise we'll hit a warning later:

  WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0
  Workqueue: events_unbound cfg80211_wiphy_work
  Call Trace:
   __ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537
   ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193
   cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
