PT-2026-106640 · Linux · Linux

CVE-2026-98311

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
wifi: virt wifi: don't transfer operstate before register
virt wifi newlink() calls netif stacked transfer operstate() before register netdevice(). If the lower device is dormant, that queues the new netdev on lweventlist while it is still uninitialized. If registration fails after that, for example because of an invalid name such as "bad/name", free netdev() immediately frees the object. A later linkwatch fire event() then use-after-frees the list entry.
Move the transfer to after netdev upper dev link(), as macvlan and ipvlan already do.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98311

Affected Products

Linux