CVE-2026-98331

Source
https://cve.org/CVERecord?id=CVE-2026-98331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98331
Downstream
Published
2026-10-06T08:46:23Z
Modified
2026-10-08T02:52:57Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
wifi: mac80211: unlist vifs when their netdev is unregistered
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: unlist vifs when their netdev is unregistered

mac80211 only removes vifs from the local->interfaces list when an interface is removed via ieee80211_if_remove(), before it unregisters the netdev. However, it's possible for a netdev to be unregistered without going through that: When the netns that holds the wiphy is destroyed, the wiphy is supposed to move to the init_ns, but that can run into allocation failures.

Then, mac80211 has an interface listed that doesn't exist, and will eventually hit

BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()! ... _cfg80211_unregister_wdev+0x24/0x36a [cfg80211] cfg80211_unregister_wdev+0x15/0x1d [cfg80211] ieee80211_remove_interfaces+0x1ff/0x257 [mac80211] ieee80211_unregister_hw+0x73/0x1d1 [mac80211] mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]

Remove the interface from the list in ->ndo_uninit if it's still around to avoid this.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98331.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
463d018323851a608eef52a9427b0585005c647f
Fixed
a22c02863439993095acd0c3db97fa53cd515f4f
Fixed
20a56e96a6f7b4dfbd13f8732fd2673409fc7ba0
Fixed
b735ad1a9aca6080192c1316cf2706e5e1318762
Fixed
d45bf731ec7085d2cc2c5d179d3b3b6c743d4fb1
Fixed
821bab0456dfca12acef6df702c8f2477d313227
Fixed
eee2efd82867b623982ac51925b5a1812a74c50d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98331.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.32
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98331.json"