CVE-2026-98337

high

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't start a ROC while scanning The ROC work can be pending when a scan starts (which requires ROC list to be empty, but that's possible), and then a new ROC can be added to the list and the work will pick it up. Avoid starting that ROC if a scan made it between things, as otherwise we'll hit a warning later: WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0 Workqueue: events_unbound cfg80211_wiphy_work Call Trace: __ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537 ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193 cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513

References

https://git.kernel.org/stable/c/81baab8b645ec532bad2b7a8464191c720ef8fd9

https://git.kernel.org/stable/c/733f0fde95392ed5f61a4e36aee661ea8d0e8581

https://git.kernel.org/stable/c/5dc8ec2f8d1d62914661577c23ec151f5c9734a4

https://git.kernel.org/stable/c/58b806f699052c572dec6cab2c376f884f27e98f

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93322

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00175