CVE-2026-98346

medium

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't get the radio mask for netdev-less wdevs cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with wdev->netdev, which can be NULL and then crashes in mac80211. To avoid that, invert the order of checks since wdev->netdev is always valid for beaconing interfaces.

References

https://git.kernel.org/stable/c/a7783e585360ee05dfe21d3173dbbe985c94f29e

https://git.kernel.org/stable/c/7166da84a7fe3553f9065782fd80299a37b150e5

https://git.kernel.org/stable/c/693d777846d525b8b218bad97a1befa5d9bd4334

https://git.kernel.org/stable/c/5b313159c970e945ee125ca87fad0d96ed913e55

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93331

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00175