{"id":"AZL-106257","summary":"CVE-2026-98338 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: ibss: ref BSS entry for joined event\n\nWhen the IBSS is joined, we only record the BSSID/channel in the event\nand look up the BSS entry when processing it. However, that's racy,\ne.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it, causing a\nwarning in the event work:\n\n  !bss\n  WARNING: net/wireless/ibss.c:37 at __cfg80211_ibss_joined+0x3d3/0x440\n  Workqueue: cfg80211 cfg80211_event_work\n   cfg80211_process_wdev_events+0x39f/0x5b0 net/wireless/util.c:1144\n   cfg80211_process_rdev_events+0xa1/0x110 net/wireless/util.c:1179\n   cfg80211_event_work+0x2f/0x40 net/wireless/core.c:393\n\nDo the lookup early (the driver is expected to only join an IBSS that\nhas a BSS entry) and keep a reference to it.","modified":"2026-10-07T14:16:59.828022598Z","published":"2026-10-06T09:18:26Z","upstream":["CVE-2026-98338"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98338"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106257.json"}}],"schema_version":"1.9.0"}