{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: ibss: ref BSS entry for joined event  When the IBSS is joined, we only record the BSSID/channel in the event and look up the BSS entry when processing it. However, that's racy, e.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it, causing a warning in the event work:    !bss   WARNING: net/wireless/ibss.c:37 at __cfg80211_ibss_joined+0x3d3/0x440   Workqueue: cfg80211 cfg80211_event_work    cfg80211_process_wdev_events+0x39f/0x5b0 net/wireless/util.c:1144    cfg80211_process_rdev_events+0xa1/0x110 net/wireless/util.c:1179    cfg80211_event_work+0x2f/0x40 net/wireless/core.c:393  Do the lookup early (the driver is expected to only join an IBSS that has a BSS entry) and keep a reference to it.",
  "id": "DEBIAN-CVE-2026-98338",
  "modified": "2026-10-07T04:47:41.545077010Z",
  "published": "2026-10-06T09:18:26.437Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98338"
    }
  ],
  "upstream": [
    "CVE-2026-98338"
  ]
}