{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98341","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.342Z","datePublished":"2026-10-06T08:46:31.585Z","dateUpdated":"2026-10-07T06:50:09.191Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:09.191Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: don't free driver-owned scan requests\n\nWhen an interface goes down while a scan is running, cfg80211 completes\nthe scan towards userspace and frees the scan request. However, the\ndriver can be convinced that it owns the request, since the cancellation\nis (intended to be) asynchronous.\n\nThe WARN_ON() in the netdev notifier was meant to catch this, but it's\nnot actually avoidable, so it triggers and we get a UAF in scan_done().\n\nThere doesn't seem to be a great way around it, so just track that the\ndriver is still convinced it owns the request, and then just free it on\ncompletion if it was already cancelled. Also remove the warnings since\nthey can trigger in the intended architecture."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Nothing from the air causes this. It needs the interface taken down during a running scan, which is done locally: link-down/dev_close to the NETDEV_DOWN branch of cfg80211_netdev_notifier_call(), or a /dev/rfkill soft-block via cfg80211_rfkill_set_block()->cfg80211_shutdown_all_interfaces(). A WiFi peer cannot cause either, so the vector is local.\nAC:L - The attacker causes both sides: start a scan (nl80211 TRIGGER_SCAN or a NetworkManager scan request), then block rfkill or bring the link down. With hw_scan drivers ieee80211_scan_cancel() only calls drv_cancel_hw_scan() and returns. ___cfg80211_scan_done() frees the request before the driver's async completion calls cfg80211_scan_done(), so the window is the whole multi-second scan.\nPR:L - Direct nl80211/rtnetlink control of an init_net wiphy needs CAP_NET_ADMIN. But on standard systemd desktops the active console user can write /dev/rfkill (uaccess rule), and an rfkill block runs dev_close() into the freeing notifier. That user can also request scans, so an ordinary local user is enough.\nUI:N - The attacker does both steps (start the scan, then rfkill-block or take the link down) without any action from another user.\nS:U - The UAF corrupts kernel heap memory under the same kernel authority. No VM, IOMMU or sandbox boundary is crossed.\nC:H - The freed cfg80211_scan_request_int is a kmalloc object whose size the attacker sets through the scan's channel count and IE length. The driver and cfg80211_scan_done() later read it (info, wdev, notified), so a reclaimed object can be used to leak kernel memory.\nI:H - cfg80211_scan_done() writes into the freed request (intreq->info, notified) and follows req.wdev from it. Reclaiming the slot with attacker-controlled data gives a write and pointer-confusion primitive that could be used for privilege escalation.\nA:H - The use-after-free in cfg80211_scan_done() reached from the mac80211 scan completion work (syzbot report) gives a KASAN splat or kernel oops, and it can be repeated at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/core.c","net/wireless/core.h","net/wireless/rdev-ops.h","net/wireless/scan.c"],"versions":[{"version":"4a58e7c38443154fce1b47910e1a9184f65c5d72","lessThan":"e8c75736cfd0c6c87562cda2312e3fe5e2227955","status":"affected","versionType":"git"},{"version":"4a58e7c38443154fce1b47910e1a9184f65c5d72","lessThan":"cf6da29d17994865f73ca70976495ea856909c63","status":"affected","versionType":"git"},{"version":"4a58e7c38443154fce1b47910e1a9184f65c5d72","lessThan":"dab68a74e90b8e07f08ed9deaa5884857a3cfe89","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/wireless/core.c","net/wireless/core.h","net/wireless/rdev-ops.h","net/wireless/scan.c"],"versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.14","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.14","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.14","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e8c75736cfd0c6c87562cda2312e3fe5e2227955"},{"url":"https://git.kernel.org/stable/c/cf6da29d17994865f73ca70976495ea856909c63"},{"url":"https://git.kernel.org/stable/c/dab68a74e90b8e07f08ed9deaa5884857a3cfe89"}],"title":"wifi: cfg80211: don't free driver-owned scan requests","x_generator":{"engine":"bippy-1.2.0"}}}}