CVE-2026-98325

medium

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: set up the TX info early to fix failure paths The previous commit 2c51457d930f ("wifi: mac80211: free ack status frame on TX header build failure") cleaned up the leak, but still left the code a bit messy and the failed SKB didn't get reported to userspace. Fix this up by initialising skb->cb[] earlier, which allows using ieee80211_free_txskb() and therefore reports it for the failure in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize() failure path with it.

References

https://git.kernel.org/stable/c/df711e9fa20d7e996711c7f43a11a71805bef78d

https://git.kernel.org/stable/c/50d3d79dc0743b616afb00d01a626c76758721f7

https://git.kernel.org/stable/c/420fcc2fdeae6ecd682d2b1605a0a54c88aed4aa

https://git.kernel.org/stable/c/36e6f0a5e6d7238f4023e77f423c1c1414374309

https://git.kernel.org/stable/c/0fb37d2b6cb829cebdaea80f39011469f474bdcc

https://git.kernel.org/stable/c/03d67414bd05b86029afc14535238a9393eac1c6

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93310

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.0018