PT-2026-106660 · Linux · Linux

CVE-2026-98331

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: unlist vifs when their netdev is unregistered
mac80211 only removes vifs from the local->interfaces list when an interface is removed via ieee80211 if remove(), before it unregisters the netdev. However, it's possible for a netdev to be unregistered without going through that: When the netns that holds the wiphy is destroyed, the wiphy is supposed to move to the init ns, but that can run into allocation failures.
Then, mac80211 has an interface listed that doesn't exist, and will eventually hit
BUG: failure at net/wireless/core.h:141/wiphy to rdev()! ... cfg80211 unregister wdev+0x24/0x36a [cfg80211] cfg80211 unregister wdev+0x15/0x1d [cfg80211] ieee80211 remove interfaces+0x1ff/0x257 [mac80211] ieee80211 unregister hw+0x73/0x1d1 [mac80211] mac80211 hwsim del radio+0x114/0x166 [mac80211 hwsim]
Remove the interface from the list in ->ndo uninit if it's still around to avoid this.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98331

Affected Products

Linux