Sceawere
Vulnerability Detail
CVE-2026-98331UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux mac80211 Use-After-Unregister Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: unlist vifs when their netdev is unregistered mac80211 only removes vifs from the local->interfaces list when an interface is removed via ieee80211_if_remove(), before it unregisters the netdev. However, it's possible for a netdev to be unregistered without going through that: When the netns that holds the wiphy is destroyed, the wiphy is supposed to move to the init_ns, but that can run into allocation failures. Then, mac80211 has an interface listed that doesn't exist, and will eventually hit BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()! ... _cfg80211_unregister_wdev+0x24/0x36a [cfg80211] cfg80211_unregister_wdev+0x15/0x1d [cfg80211] ieee80211_remove_interfaces+0x1ff/0x257 [mac80211] ieee80211_unregister_hw+0x73/0x1d1 [mac80211] mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim] Remove the interface from the list in ->ndo_uninit if it's still around to avoid this.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-10-06T09:18:25.517Z",
"pubdate": "2026-10-06T09:18:25.517Z",
"executiveSummary": "This vulnerability involves a race condition and memory management flaw in the Linux kernel's mac80211 subsystem during network interface unregistration.\nThe issue is categorized as an improper lifecycle management of virtual interfaces (vifs) leading to a kernel crash (BUG: failure at net/wireless/core.h).\nIt affects the mac80211 wireless framework when network namespaces (netns) are destroyed or when netdevs are unregistered via unconventional paths.\nThe vulnerability allows for a denial-of-service (DoS) condition, as the kernel attempts to operate on stale interface references that persist in the local->interfaces list after the corresponding netdev has been unregistered.\nExploitation requires the ability to trigger a netns teardown or interface removal process in a specific state, leading to kernel panic.\nRisk implications include system instability and potential escalation if memory corruption occurs due to lingering stale pointers in the subsystem state tracking structures.",
"technicalDetails": "The root cause of the vulnerability lies in an architectural disconnect between the mac80211 virtual interface (vif) management list and the underlying netdev lifecycle. Previously, mac80211 relied solely on ieee80211_if_remove() to prune interfaces from the local->interfaces list before unregistering the netdev. However, if a netdev is unregistered through alternative paths—specifically during the destruction of a network namespace (netns) where wiphy migration to the init_ns fails due to memory allocation exhaustion—the vif remains present in the local->interfaces list while the corresponding network device is gone.\nThis creates an inconsistent state within the kernel's wireless subsystem. Subsequent calls to teardown functions, such as ieee80211_unregister_hw() or cfg80211_unregister_wdev(), attempt to iterate over these stale, invalid interface entries. When the kernel calls wiphy_to_rdev() in net/wireless/core.h, it triggers a BUG() assertion failure because the expected rdev association is no longer valid or reachable for the phantom interface entry.\nThe attack flow typically involves an attacker or a system process initiating the removal of a wireless radio or network namespace while the interface is active. If the kernel's attempt to migrate the wiphy fails, the system enters an error recovery path that triggers the crash due to the presence of the dangling vif pointer. The vulnerability specifically impacts the cleanup logic in ieee80211_remove_interfaces and mac80211_hwsim_del_radio, which eventually call into cfg80211_unregister_wdev.\nThe exploitation path represents a classic use-after-unregister scenario where the metadata tracking structure (vif list) is not synchronized with the destruction of the data plane (netdev). By inducing memory pressure or orchestrating netns destruction concurrently with radio removal, an attacker can reliably hit the invalid memory access or the explicit kernel BUG() check, resulting in a system crash.\nThe vulnerability is localized to the interaction between mac80211 and cfg80211. Because this involves kernel-level memory management and subsystem state tracking, the impact is a local denial-of-service, though it requires no specific user authentication if the triggering actions are exposed via standard interfaces or system administration tasks."
}