CVE-2026-98311 (GCVE-0-2026-98311)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:46 – Updated: 2026-10-07 06:49
VLAI
Title
wifi: virt_wifi: don't transfer operstate before register
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: don't transfer operstate before register virt_wifi_newlink() calls netif_stacked_transfer_operstate() before register_netdevice(). If the lower device is dormant, that queues the new netdev on lweventlist while it is still uninitialized. If registration fails after that, for example because of an invalid name such as "bad/name", free_netdev() immediately frees the object. A later linkwatch_fire_event() then use-after-frees the list entry. Move the transfer to after netdev_upper_dev_link(), as macvlan and ipvlan already do.
Impacted products
Vendor Product Version
Linux Linux Affected: c7cdba31ed8b87526db978976392802d3f93110c , < ee9ea1afd6990def51d52b3a0aecd5cfcc951da0 (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < 9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225 (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < f9526054c2b2cace5916b7225603d008834ec011 (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < e8304e25c6dabb8accf38b807969438d0ce84fd7 (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < ca49763c42c1089d654bf11b037980a9ede3772c (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < 293c56a66510bb7de073a1aba388e38abddff1fb (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < b808a9af5fd21f9c68b0d024eda7535b5dce6a4e (git)
Affected: c7cdba31ed8b87526db978976392802d3f93110c , < e5c8d7acd31b27057ea42cd405d0b3ece097bc89 (git)
Create a notification for this product.
Linux Linux Affected: 5.0
Unaffected: 0 , < 5.0 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/virtual/virt_wifi.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ee9ea1afd6990def51d52b3a0aecd5cfcc951da0",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "f9526054c2b2cace5916b7225603d008834ec011",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "e8304e25c6dabb8accf38b807969438d0ce84fd7",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "ca49763c42c1089d654bf11b037980a9ede3772c",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "293c56a66510bb7de073a1aba388e38abddff1fb",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "b808a9af5fd21f9c68b0d024eda7535b5dce6a4e",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            },
            {
              "lessThan": "e5c8d7acd31b27057ea42cd405d0b3ece097bc89",
              "status": "affected",
              "version": "c7cdba31ed8b87526db978976392802d3f93110c",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/wireless/virtual/virt_wifi.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            },
            {
              "lessThan": "5.0",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "5.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don\u0027t transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice(). If the lower device is dormant, that queues the\nnew netdev on lweventlist while it is still uninitialized. If\nregistration fails after that, for example because of an invalid name\nsuch as \"bad/name\", free_netdev() immediately frees the object. A\nlater linkwatch_fire_event() then use-after-frees the list entry.\n\nMove the transfer to after netdev_upper_dev_link(), as macvlan and\nipvlan already do."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The trigger is a local RTM_NEWLINK netlink request of kind \"virt_wifi\" handled by virt_wifi_newlink(). No remote peer or WiFi frame supplies any input. The bug is a fault in the order of steps when creating the device.\nAC:L - The attacker sets up the state and triggers it alone. They bring the lower device (e.g. lo) up and set it dormant via IFLA_OPERSTATE, then send RTM_NEWLINK with an invalid name like \"bad/name\". netif_dormant_on() queues the device on lweventlist, register_netdevice() fails and free_netdev() frees the device while it is still queued. No race is involved.\nPR:L - rtnetlink_rcv_msg() and __rtnl_newlink() check CAP_NET_ADMIN only against the user namespace that owns the netns, so an unprivileged user can get it with unshare -Urn. __rtnl_newlink() also auto-loads rtnl-link-virt_wifi through request_module().\nUI:N - No victim action is needed; the attacker\u0027s own netlink messages create the dormant lower device, the failing virt_wifi link and the queued linkwatch event.\nS:U - Memory in the same kernel is corrupted and stays within the kernel\u0027s own security authority. No VM, IOMMU or sandbox boundary is crossed.\nC:H - The freed net_device is still linked into the global lweventlist. linkwatch_do_dev() later reads it (flags, state, qdisc pointers), so the attacker can reclaim the freed object with controlled data and use the resulting reads to leak memory.\nI:H - A list_add or list_del on lweventlist writes through link_watch_list into freed memory. With a reclaimed object, linkwatch_do_dev() calls dev_activate() or dev_deactivate() on qdisc pointers the attacker controls, which allows corrupting memory and hijacking control flow.\nA:H - Even without careful exploitation, the queued linkwatch_event work or any later linkwatch_fire_event() corrupts list memory or touches freed memory. That causes a kernel oops or panic, and the attacker can repeat it."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:58.266Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ee9ea1afd6990def51d52b3a0aecd5cfcc951da0"
        },
        {
          "url": "https://git.kernel.org/stable/c/9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225"
        },
        {
          "url": "https://git.kernel.org/stable/c/f9526054c2b2cace5916b7225603d008834ec011"
        },
        {
          "url": "https://git.kernel.org/stable/c/e8304e25c6dabb8accf38b807969438d0ce84fd7"
        },
        {
          "url": "https://git.kernel.org/stable/c/ca49763c42c1089d654bf11b037980a9ede3772c"
        },
        {
          "url": "https://git.kernel.org/stable/c/293c56a66510bb7de073a1aba388e38abddff1fb"
        },
        {
          "url": "https://git.kernel.org/stable/c/b808a9af5fd21f9c68b0d024eda7535b5dce6a4e"
        },
        {
          "url": "https://git.kernel.org/stable/c/e5c8d7acd31b27057ea42cd405d0b3ece097bc89"
        }
      ],
      "title": "wifi: virt_wifi: don\u0027t transfer operstate before register",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98311",
    "datePublished": "2026-10-06T08:46:07.562Z",
    "dateReserved": "2026-09-25T10:25:14.339Z",
    "dateUpdated": "2026-10-07T06:49:58.266Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98311",
      "date": "2026-10-08",
      "epss": "0.00135",
      "percentile": "0.02526"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/wireless/virtual/virt_wifi.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "ee9ea1afd6990def51d52b3a0aecd5cfcc951da0",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "f9526054c2b2cace5916b7225603d008834ec011",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e8304e25c6dabb8accf38b807969438d0ce84fd7",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ca49763c42c1089d654bf11b037980a9ede3772c",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "293c56a66510bb7de073a1aba388e38abddff1fb",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b808a9af5fd21f9c68b0d024eda7535b5dce6a4e",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e5c8d7acd31b27057ea42cd405d0b3ece097bc89",
                    "status": "affected",
                    "version": "c7cdba31ed8b87526db978976392802d3f93110c",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/net/wireless/virtual/virt_wifi.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.0"
                  },
                  {
                    "lessThan": "5.0",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don\u0027t transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice(). If the lower device is dormant, that queues the\nnew netdev on lweventlist while it is still uninitialized. If\nregistration fails after that, for example because of an invalid name\nsuch as \"bad/name\", free_netdev() immediately frees the object. A\nlater linkwatch_fire_event() then use-after-frees the list entry.\n\nMove the transfer to after netdev_upper_dev_link(), as macvlan and\nipvlan already do."
          }
        ],
        "id": "CVE-2026-98311",
        "lastModified": "2026-10-07T07:17:08.473",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:22.573",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/293c56a66510bb7de073a1aba388e38abddff1fb"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b808a9af5fd21f9c68b0d024eda7535b5dce6a4e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ca49763c42c1089d654bf11b037980a9ede3772c"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e5c8d7acd31b27057ea42cd405d0b3ece097bc89"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e8304e25c6dabb8accf38b807969438d0ce84fd7"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ee9ea1afd6990def51d52b3a0aecd5cfcc951da0"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/f9526054c2b2cace5916b7225603d008834ec011"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:47:55Z",
      "cve": "CVE-2026-98311",
      "id": "CVE-2026-98311",
      "initial_release_date": "2026-10-08T16:47:55Z",
      "product_status:known_affected": "208",
      "product_status:known_not_affected": "139",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98311",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98311.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…