Sceawere
Vulnerability Detail
CVE-2026-98341UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
cfg80211 UAF in Scan Requests
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't free driver-owned scan requests When an interface goes down while a scan is running, cfg80211 completes the scan towards userspace and frees the scan request. However, the driver can be convinced that it owns the request, since the cancellation is (intended to be) asynchronous. The WARN_ON() in the netdev notifier was meant to catch this, but it's not actually avoidable, so it triggers and we get a UAF in scan_done(). There doesn't seem to be a great way around it, so just track that the driver is still convinced it owns the request, and then just free it on completion if it was already cancelled. Also remove the warnings since they can trigger in the intended architecture.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:26.873Z",
"pubdate": "2026-10-06T09:18:26.873Z",
"executiveSummary": "A Use-After-Free (UAF) vulnerability exists in the Linux kernel cfg80211 subsystem related to the lifecycle management of scan requests. The flaw occurs when a network interface is brought down while a scan is in progress, leading to a race condition between the subsystem and the wireless driver. An attacker capable of triggering interface state changes during active scanning could potentially cause memory corruption or system instability. The vulnerability stems from conflicting ownership logic where both the subsystem and the driver attempt to manage the memory of the scan request structure. This issue affects Linux kernel versions supporting cfg80211, necessitating a fix to ensure proper request synchronization and memory deallocation patterns. The risk implies potential kernel panics or exploitation scenarios involving arbitrary code execution if an attacker can manipulate the freed memory object before it is accessed by the driver.",
"technicalDetails": "The vulnerability resides within the cfg80211 subsystem, specifically in the interaction between netdev notifier events and driver-initiated scan requests. In the original architecture, when a network interface is taken offline, cfg80211 attempts to terminate ongoing scans by notifying userspace and subsequently freeing the associated scan request object.\nThe root cause is a synchronization mismatch regarding the ownership of the scan request structure. While the cfg80211 subsystem assumes immediate ownership and initiates deallocation, the wireless driver may still hold a reference to the request, under the impression that the cancellation process is asynchronous and incomplete. Because the driver eventually triggers scan_done() to signal completion, the kernel attempts to process a request that has already been deallocated, resulting in a Use-After-Free (UAF) condition.\nHistorically, this conflict was mitigated by a WARN_ON() check in the netdev notifier intended to prevent double-free or invalid access patterns. However, the logic proved inherently flawed as the driver-subsystem race is an architectural inevitability rather than an erroneous condition. As a result, the warning frequently triggered, and the underlying memory safety violation persisted.\nThe attack flow involves an attacker monitoring or influencing the wireless subsystem to detect active scan windows. By forcing an interface to down-state via syscalls or hardware interaction exactly as the scan request is being processed, the attacker triggers the race condition. The kernel continues to execute the driver's completion handler (scan_done) on the freed pointer. Because this occurs at the kernel level, the impact is significant: the UAF allows for the corruption of the heap metadata or the redirection of kernel control flow if the freed memory is reallocated to a different kernel object before the driver accesses it.\nThe remediation involves transitioning to a state-tracking mechanism where the system explicitly tracks if the driver still claims ownership of a scan request. Instead of immediate deallocation, the subsystem marks the request as cancelled and delegates the final freeing process to the completion handler, which verifies the state before deallocating memory. This ensures that even if the netdev notifier requests a cancellation, the actual memory management remains consistent with the driver's asynchronous operation cycle."
}