CVE-2026-98236 Overview
CVE-2026-98236 is a Linux kernel vulnerability in the MHI WWAN MBIM driver (net/wwan/mhi_wwan_mbim). The mhi_mbim_rx() function ignores the return value of skb_copy_bits() when extracting datagrams from a Network Transfer Block (NTB). A malicious or malfunctioning modem can supply a Datagram Pointer Entry (DPE) that points outside the received socket buffer. The copy fails silently and the uninitialized skbn is forwarded to netif_rx(), leaking kernel heap contents into the network stack.
Critical Impact
An attached modem device can trigger disclosure of uninitialized kernel heap memory into the host network stack by crafting malformed MBIM NTB framing.
Affected Products
- Linux kernel builds including the mhi_wwan_mbim WWAN driver prior to the fix
- Systems using Qualcomm MHI-based WWAN modems with MBIM
- Stable kernel branches referenced by the fixing commits listed below
Discovery Timeline
- 2026-10-06 - CVE CVE-2026-98236 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-98236
Vulnerability Analysis
The MBIM protocol transports multiple IP datagrams inside a single NTB. Each datagram is described by a DPE containing an offset and length. The driver validates that these fields fall within the NTB itself, but does not confirm that skb_copy_bits() succeeds when extracting the payload into a freshly allocated skbn.
When a DPE references a region outside the received skb, skb_copy_bits() returns an error. The unpatched driver ignores this error and still invokes netif_rx(skbn). Because skbn was allocated without zeroing, its linear buffer retains whatever stale kernel heap data occupied that slab prior to allocation. The network stack then processes those bytes as if they were received frames.
Researchers verified the condition in a QEMU guest using a fault injector that aimed a DPE outside the NTB. The unpatched driver forwarded the uninitialized skbn, observable as frames with an "unknown protocol" field reflecting heap contents never written by the driver.
Root Cause
The root cause is a missing return value check on skb_copy_bits() inside mhi_mbim_rx(). The function treats the copy as infallible even though DPE-driven offsets can produce a failed copy against the actual skb layout.
Attack Vector
Exploitation requires the ability to supply crafted MBIM framing to the host. This is possible from a malicious or compromised WWAN modem attached over MHI, or from a device impersonating one. The attacker influences DPE offset and length fields in the NTB to force skb_copy_bits() failure, inducing the driver to pass uninitialized memory into netif_rx().
The vulnerability discloses kernel heap memory into the network stack. See the upstream fixing commits for the exact code paths, including Kernel Git Commit 02eba5f and Kernel Git Commit 7e98216.
Detection Methods for CVE-2026-98236
Indicators of Compromise
- Unexpected rx error counter increases on wwan interfaces after applying the patch, indicating DPE validation failures.
- Kernel log entries from the MBIM driver reporting dropped datagrams via mhi_mbim_rx_drop().
- Received frames logged by higher layers as having unknown or inconsistent protocol fields on WWAN interfaces.
Detection Strategies
- Inventory running kernels and confirm whether the mhi_wwan_mbim module is loaded with lsmod | grep mhi_wwan_mbim.
- Compare installed kernel versions against the stable branches that include the fixing commits referenced in the NVD entry.
- Monitor ip -s link show and /proc/net/dev for anomalous rx error rates on WWAN interfaces.
Monitoring Recommendations
- Forward kernel ring buffer entries from WWAN-equipped endpoints into a central log pipeline for review.
- Alert on sustained rx error growth on any wwan* interface, which may indicate a hostile or faulty modem producing invalid NTBs.
- Track MHI subsystem driver load events on fleet endpoints and correlate with device enumeration logs.
How to Mitigate CVE-2026-98236
Immediate Actions Required
- Update to a stable Linux kernel release that incorporates the upstream fix adding the skb_copy_bits() return value check and the mhi_mbim_rx_drop() helper.
- On systems that do not require cellular connectivity, unload the mhi_wwan_mbim module and blacklist it until patched.
- Restrict physical and USB-level access to endpoints that expose MHI WWAN hardware.
Patch Information
The fix is distributed across multiple stable branches. Reference commits include Kernel Git Commit 02eba5f, Kernel Git Commit 298659c, Kernel Git Commit 31550d5, Kernel Git Commit 350fd31, Kernel Git Commit 650af68, Kernel Git Commit 7e98216, and Kernel Git Commit dd136f1. The patch checks the result of skb_copy_bits() and routes failures through mhi_mbim_rx_drop(), which frees the skbn and increments the rx error counter.
Workarounds
- Blacklist the mhi_wwan_mbim kernel module on endpoints that do not use cellular WWAN connectivity.
- Disable or physically disconnect MBIM-capable modems on systems that cannot be patched immediately.
- Isolate WWAN-equipped hosts on segmented networks to limit the blast radius of any disclosed heap memory being reflected into other services.
# Prevent the vulnerable driver from loading until the kernel is patched
echo 'blacklist mhi_wwan_mbim' | sudo tee /etc/modprobe.d/blacklist-mhi-mbim.conf
sudo modprobe -r mhi_wwan_mbim
sudo update-initramfs -u
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.