Answer in brief
CVE-2026-98327 records a Unknown severity vulnerability in wifi: mac80211: mesh: reset the CSA state when leaving. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b8456a14e9d2770846fcf74de18ff95b676149a3 <aba8dfb45864441199748c33ce3c1c8ca121c8bd || >=b8456a14e9d2770846fcf74de18ff95b676149a3 <bd3b21145ae2e781daac1bbd19216a63ab4e0cbd || >=b8456a14e9d2770846fcf74de18ff95b676149a3 <ba5bf83a81e8832cb84bb3a2da67512f81f57a02 || >=b8456a14e9d2770846fcf74de18ff95b676149a3 <860134b3af77970e006feab7e5decb8c84771c7f | aba8dfb45864441199748c33ce3c1c8ca121c8bd, bd3b21145ae2e781daac1bbd19216a63ab4e0cbd, ba5bf83a81e8832cb84bb3a2da67512f81f57a02, 860134b3af77970e006feab7e5decb8c84771c7f |
| Linux/Linuxgeneric | 3.13 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: reset the CSA state when leaving ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it. Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak in this case, so things can get mixed up in addition to the memory leak. Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.
Quoted source text, attributed separately from HOL analysis.