{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "aaa016ccd5df89d73483d0d51ee1f692978ccc35"
            },
            {
              "fixed": "5dc8ec2f8d1d62914661577c23ec151f5c9734a4"
            },
            {
              "fixed": "81baab8b645ec532bad2b7a8464191c720ef8fd9"
            },
            {
              "fixed": "58b806f699052c572dec6cab2c376f884f27e98f"
            },
            {
              "fixed": "733f0fde95392ed5f61a4e36aee661ea8d0e8581"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.5.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98337.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't start a ROC while scanning\n\nThe ROC work can be pending when a scan starts (which requires\nROC list to be empty, but that's possible), and then a new ROC\ncan be added to the list and the work will pick it up.\n\nAvoid starting that ROC if a scan made it between things, as\notherwise we'll hit a warning later:\n\n  WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0\n  Workqueue: events_unbound cfg80211_wiphy_work\n  Call Trace:\n   __ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537\n   ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193\n   cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513",
  "id": "CVE-2026-98337",
  "modified": "2026-10-08T02:31:07.437035569Z",
  "published": "2026-10-06T08:46:28.420Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/58b806f699052c572dec6cab2c376f884f27e98f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5dc8ec2f8d1d62914661577c23ec151f5c9734a4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/733f0fde95392ed5f61a4e36aee661ea8d0e8581"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/81baab8b645ec532bad2b7a8464191c720ef8fd9"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98337.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98337"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "wifi: mac80211: don't start a ROC while scanning"
}