CVE-2026-98351

Source
https://cve.org/CVERecord?id=CVE-2026-98351
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98351.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98351
Downstream
Published
2026-10-06T08:46:39Z
Modified
2026-10-07T02:47:34Z
Summary
wifi: virt_wifi: free skb when disconnected
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: free skb when disconnected

When the simulated link is disconnected, virt_wifi_start_xmit() returns NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this return value as consumed, so every packet sent while disconnected leaks its skb.

Free the skb before returning the drop status.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98351.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c7cdba31ed8b87526db978976392802d3f93110c
Fixed
38d3a5df85345f158f78b478b265ca906224454e
Fixed
ee053ea35c759135460f03d1c574f4ed08de844a
Fixed
d177eca79e1106834bc423d3969a4a2e3987996a
Fixed
36727a702cf8e3399e3da60d0856378f6afcfb34
Fixed
56469996c10a0240653fc00576b4d33bdfb4cc51
Fixed
4f266738af45675faa0e8afee08c6e780afa8b06
Fixed
46371442847a725cc0df3697fea2eba1dd54b82b
Fixed
f9edf7cf63b96d2b776fca8d258d3c5256e40c8e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98351.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98351.json"