{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98311","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.339Z","datePublished":"2026-10-06T08:46:07.562Z","dateUpdated":"2026-10-07T06:49:58.266Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:58.266Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don't transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice(). If the lower device is dormant, that queues the\nnew netdev on lweventlist while it is still uninitialized. If\nregistration fails after that, for example because of an invalid name\nsuch as \"bad/name\", free_netdev() immediately frees the object. A\nlater linkwatch_fire_event() then use-after-frees the list entry.\n\nMove the transfer to after netdev_upper_dev_link(), as macvlan and\nipvlan already do."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is a local RTM_NEWLINK netlink request of kind \"virt_wifi\" handled by virt_wifi_newlink(). No remote peer or WiFi frame supplies any input. The bug is a fault in the order of steps when creating the device.\nAC:L - The attacker sets up the state and triggers it alone. They bring the lower device (e.g. lo) up and set it dormant via IFLA_OPERSTATE, then send RTM_NEWLINK with an invalid name like \"bad/name\". netif_dormant_on() queues the device on lweventlist, register_netdevice() fails and free_netdev() frees the device while it is still queued. No race is involved.\nPR:L - rtnetlink_rcv_msg() and __rtnl_newlink() check CAP_NET_ADMIN only against the user namespace that owns the netns, so an unprivileged user can get it with unshare -Urn. __rtnl_newlink() also auto-loads rtnl-link-virt_wifi through request_module().\nUI:N - No victim action is needed; the attacker's own netlink messages create the dormant lower device, the failing virt_wifi link and the queued linkwatch event.\nS:U - Memory in the same kernel is corrupted and stays within the kernel's own security authority. No VM, IOMMU or sandbox boundary is crossed.\nC:H - The freed net_device is still linked into the global lweventlist. linkwatch_do_dev() later reads it (flags, state, qdisc pointers), so the attacker can reclaim the freed object with controlled data and use the resulting reads to leak memory.\nI:H - A list_add or list_del on lweventlist writes through link_watch_list into freed memory. With a reclaimed object, linkwatch_do_dev() calls dev_activate() or dev_deactivate() on qdisc pointers the attacker controls, which allows corrupting memory and hijacking control flow.\nA:H - Even without careful exploitation, the queued linkwatch_event work or any later linkwatch_fire_event() corrupts list memory or touches freed memory. That causes a kernel oops or panic, and the attacker can repeat it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/virtual/virt_wifi.c"],"versions":[{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"ee9ea1afd6990def51d52b3a0aecd5cfcc951da0","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"f9526054c2b2cace5916b7225603d008834ec011","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"e8304e25c6dabb8accf38b807969438d0ce84fd7","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"ca49763c42c1089d654bf11b037980a9ede3772c","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"293c56a66510bb7de073a1aba388e38abddff1fb","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"b808a9af5fd21f9c68b0d024eda7535b5dce6a4e","status":"affected","versionType":"git"},{"version":"c7cdba31ed8b87526db978976392802d3f93110c","lessThan":"e5c8d7acd31b27057ea42cd405d0b3ece097bc89","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/virtual/virt_wifi.c"],"versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ee9ea1afd6990def51d52b3a0aecd5cfcc951da0"},{"url":"https://git.kernel.org/stable/c/9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225"},{"url":"https://git.kernel.org/stable/c/f9526054c2b2cace5916b7225603d008834ec011"},{"url":"https://git.kernel.org/stable/c/e8304e25c6dabb8accf38b807969438d0ce84fd7"},{"url":"https://git.kernel.org/stable/c/ca49763c42c1089d654bf11b037980a9ede3772c"},{"url":"https://git.kernel.org/stable/c/293c56a66510bb7de073a1aba388e38abddff1fb"},{"url":"https://git.kernel.org/stable/c/b808a9af5fd21f9c68b0d024eda7535b5dce6a4e"},{"url":"https://git.kernel.org/stable/c/e5c8d7acd31b27057ea42cd405d0b3ece097bc89"}],"title":"wifi: virt_wifi: don't transfer operstate before register","x_generator":{"engine":"bippy-1.2.0"}}}}