{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "79af1f866193de29e65a4dba7d0dab14b0c0ff93"
            },
            {
              "fixed": "b7b7d46ec4fa127767931938b282c361c0519af6"
            },
            {
              "fixed": "abe15e643e576459469867758ae9c586a7bab95d"
            },
            {
              "fixed": "46c223468537a05a404699771cd3e68532dab5e6"
            },
            {
              "fixed": "2b04d6556964ae9f89819b86a0a7801e39c3aae5"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.15.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98182.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: refuse to make a monitor active when it has no queue\n\nA monitor interface only gets a TXQ if it's created active, and one can't\nbe added later. Setting the flag on a down interface is still allowed, so\nthe driver is handed a monitor with no queue. ath9k dereferences it:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000066\n  RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k]\n   ath9k_add_interface+0x10c/0x140 [ath9k]\n   drv_add_interface+0x54/0x250 [mac80211]\n   ieee80211_do_open+0x32f/0x800 [mac80211]\n\nReached with CAP_NET_ADMIN by \"iw dev X set monitor active\" followed by\n\"ip link set X up\". RTNL is held, so netlink operations block behind it.\n\nRefuse the flag when there is no queue to give.",
  "id": "CVE-2026-98182",
  "modified": "2026-10-08T02:30:40.968276429Z",
  "published": "2026-10-06T08:44:25.219Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2b04d6556964ae9f89819b86a0a7801e39c3aae5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/46c223468537a05a404699771cd3e68532dab5e6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/abe15e643e576459469867758ae9c586a7bab95d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b7b7d46ec4fa127767931938b282c361c0519af6"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98182.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98182"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "wifi: mac80211: refuse to make a monitor active when it has no queue"
}