KernelScan.io

HIGH Introduced in 5.4

cfg80211 BssEntry Panic

CVE-2026-98339

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.5MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't filter by BSS type when removing stale entries When an assoc AP switches to a channel that already has a BSS entry, cfg80211_update_assoc_bss_entry() removes that entry before rehashing the real one, since the two would otherwise collide in the BSS rbtree. The lookup for that entry also required it to match the connection's BSS type, so an entry advertising e.g. the IBSS capability bit was left in place, and the following cfg80211_rehash_bss() then ran into it: WARN_ON(!cmp) Changing the type shouldn't really happen, but can be triggered by a rogue AP/device, so drop the check and remove any entries matching the comparison.

02

Engine v0.7.0

Risk summary

A rogue WiFi access point within radio range can trigger a kernel warning and potential panic on a victim device by advertising a mismatched BSS type during a channel switch. The stale entry left in the kernel's BSS search tree causes a tree integrity violation. No privileges on the victim device and no user interaction are required.

Affectednet/wireless/scan.c (cfg80211)

Vulnerability analysis

When a WiFi access point changes channels, the kernel updates its internal BSS tracking structures and must remove any stale duplicate entry from the BSS search tree before re-inserting the updated one. However, the cleanup code also required the stale entry to match the connection's BSS type, so an entry advertising a different network type (such as IBSS instead of infrastructure) was skipped and left in place. The leftover duplicate then caused a tree integrity violation that triggers a kernel warning, which can panic the kernel if warnings are configured as fatal. The fix removes the BSS type filter during cleanup so any matching entry is removed regardless of its advertised type. A rogue WiFi access point within radio range can trigger this by changing its advertised BSS type during a channel switch, requiring no privileges on the victim device and no user interaction.

03

BranchIntroducedFixed inPatch commit
5.105.45.10.2716ef87a853327
5.155.45.15.2221380ee3a202d
6.15.46.1.189fb445ec7480d
6.65.46.6.15865fdb973bd90
6.125.46.12.11264e23a36d8f0
6.185.46.18.546d2fd2618567
7.25.47.2.80aa44982125c
mainline5.47.3-rc4b377e1000d96