PT-2026-106640 · Linux · Linux
CVE-2026-98311
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
wifi: virt wifi: don't transfer operstate before register
virt wifi newlink() calls netif stacked transfer operstate() before
register netdevice(). If the lower device is dormant, that queues the
new netdev on lweventlist while it is still uninitialized. If
registration fails after that, for example because of an invalid name
such as "bad/name", free netdev() immediately frees the object. A
later linkwatch fire event() then use-after-frees the list entry.
Move the transfer to after netdev upper dev link(), as macvlan and
ipvlan already do.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux