{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "d6a83228823fc0cc8d79d95c9f0bf568b7317862"
            },
            {
              "fixed": "d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32"
            },
            {
              "fixed": "5d5ff5b36f5748a2a077f875a73ccb26860d3fcc"
            },
            {
              "fixed": "6eac225f59c1c2277ac74f8a716d6df0ba3b8d28"
            },
            {
              "fixed": "3f28551d0241254a75626d868041c6340285088b"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.9.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98334.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: reset state when starting AP fails\n\nieee80211_start_ap() can set enable_beacon (and beacon_int) and fail\nlater, leaving it set forever. Scanning can then attempt to restore\nbeaconing on such an interface, leading to:\n\n  Oops: divide error: 0000 [#1] SMP KASAN NOPTI\n  RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00\n  Call Trace:\n   drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160\n   __ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519\n   ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193\n   cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538\n\nin hwsim. Also, cfg80211 then allows changing the interface type,\nand the off-channel path getgs confused about beaconing as well,\nleading to another warning:\n\n  WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880\n   ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427\n   ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122\n   ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]\n   __ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882\n\nReset the state on failures to always have it correct.",
  "id": "CVE-2026-98334",
  "modified": "2026-10-08T02:31:07.862057578Z",
  "published": "2026-10-06T08:46:25.992Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3f28551d0241254a75626d868041c6340285088b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5d5ff5b36f5748a2a077f875a73ccb26860d3fcc"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/6eac225f59c1c2277ac74f8a716d6df0ba3b8d28"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d83da43e9b3b3b1bad99ac5a1065f1c63ad5fc32"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98334.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98334"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "wifi: mac80211: reset state when starting AP fails"
}