Bug 2546365 (CVE-2026-98327) - CVE-2026-98327 kernel: wifi: mac80211: mesh: reset the CSA state when leaving
Summary: CVE-2026-98327 kernel: wifi: mac80211: mesh: reset the CSA state when leaving
Keywords:
Status: NEW
Alias: CVE-2026-98327
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:06 UTC by OSIDB Bzimport
Modified: 2026-10-10 08:49 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:06:47 UTC
In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: mesh: reset the CSA state when leaving

ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.
Leaving the mesh while a switch is still pending therefore leaks it.

Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak
in this case, so things can get mixed up in addition to the memory
leak.

Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.


Note You need to log in before you can comment on or make changes to this bug.