{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: mesh: release the channel if start fails  ieee80211_join_mesh() acquires a channel context and then calls ieee80211_start_mesh(), which can fail. In that case, the chanctx isn't released then interface removal will attempt to unassign it after it's removed from the driver, hitting:    wlan0: Failed check-sdata-in-driver check, flags: 0x0   WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx    ieee80211_assign_link_chanctx    __ieee80211_link_release_channel    ieee80211_link_release_channel    ieee80211_teardown_sdata    unregister_netdevice_many_notify    _cfg80211_unregister_wdev    ieee80211_remove_interfaces    ieee80211_unregister_hw    mac80211_hwsim_del_radio    hwsim_exit_net  Correctly release the channel on start failures.",
  "id": "DEBIAN-CVE-2026-98326",
  "modified": "2026-10-07T04:47:39.831232398Z",
  "published": "2026-10-06T09:18:24.840Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98326"
    }
  ],
  "upstream": [
    "CVE-2026-98326"
  ]
}