{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98331","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.341Z","datePublished":"2026-10-06T08:46:23.481Z","dateUpdated":"2026-10-07T06:50:06.466Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:06.466Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: unlist vifs when their netdev is unregistered\n\nmac80211 only removes vifs from the local->interfaces list when\nan interface is removed via ieee80211_if_remove(), before it\nunregisters the netdev. However, it's possible for a netdev to\nbe unregistered without going through that: When the netns that\nholds the wiphy is destroyed, the wiphy is supposed to move to\nthe init_ns, but that can run into allocation failures.\n\nThen, mac80211 has an interface listed that doesn't exist, and\nwill eventually hit\n\n  BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!\n  ...\n  _cfg80211_unregister_wdev+0x24/0x36a [cfg80211]\n  cfg80211_unregister_wdev+0x15/0x1d [cfg80211]\n  ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]\n  ieee80211_unregister_hw+0x73/0x1d1 [mac80211]\n  mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]\n\nRemove the interface from the list in ->ndo_uninit if it's still\naround to avoid this."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is local: tearing down a netns that holds a mac80211 wiphy runs cfg80211_pernet_exit()->cfg80211_switch_netns(). When dev_change_net_namespace() fails there, default_device_exit_batch() unregisters the netdev while ieee80211_uninit() leaves its sdata on local->interfaces. No WiFi frame supplies the failing state.\nAC:H - It needs a wiphy already moved into an attacker-controlled netns (an admin step), plus a failed move back. The attacker can force the failure: an altname on the wlan netdev that clashes with an init_net name makes __dev_change_net_namespace() return -EEXIST, because cfg80211 doesn't strip altnames. The rare alternative is an allocation failure.\nPR:L - With a phy delegated to a container, root in that user-namespace-owned netns, which is unprivileged on the host, can add the altname via RTM_NEWLINKPROP and destroy the netns. Moving a phy out of init_net yourself needs init-ns CAP_NET_ADMIN, and hwsim radios made in a user netns are deleted by hwsim_exit_net() before cfg80211 runs.\nUI:N - The container root adds the altname and exits the namespace on their own. No other user has to do anything.\nS:U - This is memory corruption in the host kernel's mac80211 interface list. Exploiting it is ordinary kernel privilege escalation within the same kernel authority; no hypervisor or IOMMU boundary is involved.\nC:H - The netdev is freed via needs_free_netdev, but its sdata stays on local->interfaces. Every received frame then makes __ieee80211_rx_handle_packet() read the freed sdata through list_for_each_entry_rcu(), which gives a use-after-free read of an object an attacker can reallocate.\nI:H - Later removal of a neighbouring interface (list_del_rcu) and ieee80211_remove_interfaces() write into and dereference the stale sdata. That is a use-after-free write that heap reallocation could turn into memory corruption.\nA:H - The dangling entry crashes the kernel: the commit shows a BUG in wiphy_to_rdev() reached from ieee80211_remove_interfaces() during ieee80211_unregister_hw(), and frame RX can touch freed memory."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/iface.c"],"versions":[{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"a22c02863439993095acd0c3db97fa53cd515f4f","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"20a56e96a6f7b4dfbd13f8732fd2673409fc7ba0","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"b735ad1a9aca6080192c1316cf2706e5e1318762","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"d45bf731ec7085d2cc2c5d179d3b3b6c743d4fb1","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"821bab0456dfca12acef6df702c8f2477d313227","status":"affected","versionType":"git"},{"version":"463d018323851a608eef52a9427b0585005c647f","lessThan":"eee2efd82867b623982ac51925b5a1812a74c50d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mac80211/iface.c"],"versions":[{"version":"2.6.32","status":"affected"},{"version":"0","lessThan":"2.6.32","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.32","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a22c02863439993095acd0c3db97fa53cd515f4f"},{"url":"https://git.kernel.org/stable/c/20a56e96a6f7b4dfbd13f8732fd2673409fc7ba0"},{"url":"https://git.kernel.org/stable/c/b735ad1a9aca6080192c1316cf2706e5e1318762"},{"url":"https://git.kernel.org/stable/c/d45bf731ec7085d2cc2c5d179d3b3b6c743d4fb1"},{"url":"https://git.kernel.org/stable/c/821bab0456dfca12acef6df702c8f2477d313227"},{"url":"https://git.kernel.org/stable/c/eee2efd82867b623982ac51925b5a1812a74c50d"}],"title":"wifi: mac80211: unlist vifs when their netdev is unregistered","x_generator":{"engine":"bippy-1.2.0"}}}}