---
id: CVE-2026-98338
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: cfg80211: ibss: ref BSS entry for joined event

  When the IBSS is joined, we only record the BSSID/channel in the event
  and look up the BSS entry when processing i…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: cfg80211: ibss: ref BSS entry for joined event

  When the IBSS is joined, we only record the BSSID/channel in the event
  and look up the BSS entry when processing i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 667503ddcb96f3b10211f997fe55907fa7509841 <
    b0e3f019e461ac42e45aa3ec1216cefaca2f4a8b
  - >-
    Linux >= 667503ddcb96f3b10211f997fe55907fa7509841 <
    708f9d43d6a2eb9c6b83fe62af628de9dffd9314
  - Linux 2.6.32
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:26.437'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98338'
references:
  - url: 'https://git.kernel.org/stable/c/708f9d43d6a2eb9c6b83fe62af628de9dffd9314'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b0e3f019e461ac42e45aa3ec1216cefaca2f4a8b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.400Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: ibss: ref BSS entry for joined event

When the IBSS is joined, we only record the BSSID/channel in the event
and look up the BSS entry when processing it. However, that's racy,
e.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it, causing a
warning in the event work:

  !bss
  WARNING: net/wireless/ibss.c:37 at __cfg80211_ibss_joined+0x3d3/0x440
  Workqueue: cfg80211 cfg80211_event_work
   cfg80211_process_wdev_events+0x39f/0x5b0 net/wireless/util.c:1144
   cfg80211_process_rdev_events+0xa1/0x110 net/wireless/util.c:1179
   cfg80211_event_work+0x2f/0x40 net/wireless/core.c:393

Do the lookup early (the driver is expected to only join an IBSS that
has a BSS entry) and keep a reference to it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
