Sceawere
Vulnerability Detail
CVE-2026-98330UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
cfg80211 Use-After-Free NetNS Exit
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: get the wiphy out of a dying network namespace When a network namespace is destroyed, cfg80211_pernet_exit() moves any wiphy back to the initial namespace, and just warns if that fails. But moving an interface can fail (due to allocation failures), and then the wiphy is left behind with a garbage netns pointer: Kernel mode fault at addr 0x30 genlmsg_multicast_netns.constprop.0+0x46/0xcf [cfg80211] nl80211_notify_wiphy+0xcd/0xe8 [cfg80211] wiphy_unregister+0x169/0x3fc [cfg80211] Note that commit debac3a20dec ("net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().") fixed another path that could reach it without allocation failures. Remove interfaces that cannot be moved instead of failing the switch, so that the wiphy always ends up in the initial namespace. In this case the netdev core will unregister the interfaces anyway.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-10-06T09:18:25.387Z",
"pubdate": "2026-10-06T09:18:25.387Z",
"executiveSummary": "A memory corruption vulnerability exists in the Linux kernel cfg80211 subsystem during network namespace (netns) teardown.\nThe issue stems from a failure to correctly relocate wiphy structures when a network namespace is destroyed, leading to a dangling netns pointer.\nThis vulnerability allows an attacker to trigger a kernel mode fault, resulting in a denial-of-service (DoS) condition via kernel panic.\nThe affected component is the cfg80211 framework, specifically within the pernet exit routine responsible for cleanup operations.\nSuccessful exploitation requires the ability to trigger namespace destruction while the system fails to allocate resources for the wiphy relocation.\nThe risk implication is significant as it compromises kernel stability; however, it generally requires local access to the system to orchestrate namespace lifecycle events.\nThe vulnerability highlights a lack of robustness in handling failure paths during resource migration in the Linux networking stack.",
"technicalDetails": "The root cause of this vulnerability is improper error handling in cfg80211_pernet_exit() when attempting to migrate a wiphy structure back to the initial network namespace during namespace teardown.\nWhen a network namespace is destroyed, the kernel attempts to move associated wiphy devices to the initial_net namespace to prevent them from becoming orphaned. If the reallocation fails due to memory pressure or internal allocation failures, the code previously issued a warning but allowed the wiphy to remain associated with the dying namespace structure.\nThis results in a stale or 'garbage' netns pointer being stored within the wiphy object. Subsequent operations that reference this pointer—such as netlink notifications via genlmsg_multicast_netns—dereference memory that is in the process of being deallocated or has already been freed.\nThe attack flow involves triggering the destruction of a network namespace while simultaneously inducing system conditions that ensure the wiphy relocation fails (e.g., memory exhaustion or heavy kernel memory pressure). Once the namespace is torn down, any triggered kernel event that necessitates an nl80211_notify_wiphy call will access the invalid memory address.\nSpecifically, the call stack leading to the fault includes wiphy_unregister, which calls nl80211_notify_wiphy, subsequently triggering genlmsg_multicast_netns.constprop.0. The kernel fault at addr 0x30 indicates a null or corrupted pointer dereference occurring during the multicast notification process.\nThe vulnerable component is the cfg80211 subsystem within the Linux kernel. The fix involves changing the logic from failing the switch to explicitly removing the interfaces that cannot be moved. By forcing the unregistration of these interfaces, the kernel ensures that the wiphy structure is cleanly disposed of rather than maintaining an association with an invalid netns object.\nThis vulnerability is categorized as a use-after-free or invalid pointer dereference, depending on the state of the netns structure at the time of access. It poses a high risk of kernel instability as the error occurs in critical networking cleanup paths."
}