wifi: mac80211: mesh: reset the CSA state when leaving

Summary

CVECVE-2026-98327
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:24 UTC
Updated2026-10-06 09:18:24 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mesh: reset the CSA state when leaving ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes. Leaving the mesh while a switch is still pending therefore leaks it. Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak in this case, so things can get mixed up in addition to the memory leak. Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b8456a14e9d2770846fcf74de18ff95b676149a3 aba8dfb45864441199748c33ce3c1c8ca121c8bd git Not specified
CNA Linux Linux affected b8456a14e9d2770846fcf74de18ff95b676149a3 bd3b21145ae2e781daac1bbd19216a63ab4e0cbd git Not specified
CNA Linux Linux affected b8456a14e9d2770846fcf74de18ff95b676149a3 ba5bf83a81e8832cb84bb3a2da67512f81f57a02 git Not specified
CNA Linux Linux affected b8456a14e9d2770846fcf74de18ff95b676149a3 860134b3af77970e006feab7e5decb8c84771c7f git Not specified
CNA Linux Linux affected 3.13 Not specified
CNA Linux Linux unaffected 3.13 semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/aba8dfb45864441199748c33ce3c1c8ca121c8bd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/860134b3af77970e006feab7e5decb8c84771c7f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ba5bf83a81e8832cb84bb3a2da67512f81f57a02 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bd3b21145ae2e781daac1bbd19216a63ab4e0cbd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report