{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98330","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.341Z","datePublished":"2026-10-06T08:46:22.688Z","dateUpdated":"2026-10-07T06:50:05.324Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:05.324Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: get the wiphy out of a dying network namespace\n\nWhen a network namespace is destroyed, cfg80211_pernet_exit() moves any\nwiphy back to the initial namespace, and just warns if that fails. But\nmoving an interface can fail (due to allocation failures), and then the\nwiphy is left behind with a garbage netns pointer:\n\n  Kernel mode fault at addr 0x30\n  genlmsg_multicast_netns.constprop.0+0x46/0xcf [cfg80211]\n  nl80211_notify_wiphy+0xcd/0xe8 [cfg80211]\n  wiphy_unregister+0x169/0x3fc [cfg80211]\n\nNote that commit debac3a20dec (\"net: Remove conflicting altnames for\ndying netns in __dev_change_net_namespace().\") fixed another path\nthat could reach it without allocation failures.\n\nRemove interfaces that cannot be moved instead of failing the switch,\nso that the wiphy always ends up in the initial namespace. In this\ncase the netdev core will unregister the interfaces anyway."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Everything is local netlink: NL80211_CMD_SET_WIPHY_NETNS moves the wiphy into a namespace, RTM_NEWLINKPROP adds an altname, and the namespace is then torn down. cfg80211_pernet_exit() calls __cfg80211_switch_netns(); dev_change_net_namespace() fails and the wiphy keeps a pointer to the freed netns. No WiFi frame is involved.\nAC:H - A wiphy only reaches a non-init netns if real root delegates it, since hwsim radios made in a userns are deleted by hwsim_exit_net() first. The forced failure (an altname clashing with an init_net device) works only on kernels without debac3a20dec; on others the switch fails only on allocation failure. The attacker cannot cause either precondition.\nPR:L - Once a wiphy has been delegated to a container, container root needs only CAP_NET_ADMIN in its own user namespace. That passes GENL_UNS_ADMIN_PERM and the ns_capable() check on the target in nl80211_wiphy_netns() for a nested netns, and lets it add the clashing altname with RTM_NEWLINKPROP. No init-namespace privilege is required.\nUI:N - The attacker moves the wiphy, adds the altname and destroys the nested netns on their own, so no victim action is needed.\nS:U - The dangling wiphy netns pointer is a kernel memory-safety bug inside the same kernel security authority. No VM or IOMMU boundary is crossed.\nC:H - After the switch fails, rdev->wiphy keeps a pointer to a freed struct net from net_cachep. Later wiphy_net() users such as nl80211_notify_wiphy() and genlmsg_multicast_netns() dereference that freed object, a use-after-free that can be exploited for kernel memory disclosure.\nI:H - The freed struct net can be reallocated, for example by the attacker creating new namespaces. The stale wiphy then works on attacker-influenced net state, and this use-after-free of a core kernel object could be exploited for memory corruption.\nA:H - syzbot hit a kernel fault in genlmsg_multicast_netns() via nl80211_notify_wiphy() in wiphy_unregister() when it touched the dangling netns pointer, which crashes the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/core.c"],"versions":[{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"caa02072b2986d4b0e7a824de05782ef7b03a0ba","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"b949b2720688691f1e41bdbfbe3df2b6dc77c34d","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"4635b1a1c1d693178a537446a6e09963f0fdae52","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/core.c"],"versions":[{"version":"2.6.32","status":"affected"},{"version":"0","lessThan":"2.6.32","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/caa02072b2986d4b0e7a824de05782ef7b03a0ba"},{"url":"https://git.kernel.org/stable/c/b949b2720688691f1e41bdbfbe3df2b6dc77c34d"},{"url":"https://git.kernel.org/stable/c/4635b1a1c1d693178a537446a6e09963f0fdae52"}],"title":"wifi: cfg80211: get the wiphy out of a dying network namespace","x_generator":{"engine":"bippy-1.2.0"}}}}