Skip to main content
Vulnerability Database/CVE-2026-98330

CVE-2026-98330: Linux Kernel Privilege Escalation Vulnerability

CVE-2026-98330 is a privilege escalation vulnerability in the Linux kernel cfg80211 subsystem affecting network namespace handling. This post explains the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-98330 Overview

CVE-2026-98330 is a Linux kernel vulnerability in the cfg80211 wireless configuration subsystem. The flaw occurs when a network namespace is destroyed and cfg80211_pernet_exit() attempts to move associated wiphy devices back to the initial namespace. If moving an interface fails due to an allocation failure, the wiphy is left behind with a stale netns pointer. Subsequent operations such as wiphy_unregister() and nl80211_notify_wiphy() then dereference invalid memory, triggering a kernel-mode fault. The vulnerability affects local attackers with low privileges and can lead to confidentiality, integrity, and availability impact on the host.

Critical Impact

A local attacker able to trigger network namespace destruction under memory pressure can cause a kernel fault at address 0x30, leading to denial of service and potential memory corruption in the Linux wireless stack.

Affected Products

  • Linux kernel versions containing the vulnerable cfg80211_pernet_exit() code path
  • Distributions shipping the affected cfg80211 module prior to the referenced stable commits
  • Systems using wireless networking with container or network namespace workloads

Discovery Timeline

  • 2026-10-06 - CVE-2026-98330 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98330

Vulnerability Analysis

The vulnerability resides in the Linux kernel cfg80211 subsystem, which manages wireless device configuration. When a network namespace is torn down, cfg80211_pernet_exit() iterates registered wiphy devices and attempts to migrate them back into the initial namespace. The current implementation only emits a warning if the migration fails, leaving the wiphy associated with a dying namespace.

If the interface move fails (for example, due to a kernel allocation failure during the rename or re-registration path), the wiphy retains a pointer to the destroyed net structure. Later notification paths such as nl80211_notify_wiphy() and genlmsg_multicast_netns() dereference this garbage netns pointer, resulting in a kernel-mode fault at offset 0x30.

This is a use-after-free style defect in kernel namespace lifecycle management. A related path previously addressed by commit debac3a20dec ("net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().") illustrates that multiple code paths can reach this failure mode.

Root Cause

The root cause is incomplete error handling in cfg80211_pernet_exit(). The function assumes namespace migration always succeeds, treating failures only as warnings. When migration fails, the wiphy continues to reference a destroyed network namespace, violating the invariant that wiphys always live in a valid namespace after pernet_exit.

Attack Vector

The attack vector is local with high attack complexity. An attacker requires low privileges and must induce memory allocation failures while triggering network namespace destruction that involves a wiphy. Successful exploitation produces kernel memory corruption through the stale netns pointer dereference in genlmsg_multicast_netns.constprop.0+0x46/0xcf within the cfg80211 module.

The fix removes interfaces that cannot be moved rather than failing the namespace switch. This ensures the wiphy always ends up in the initial namespace, and the netdev core unregisters the orphaned interfaces. See the upstream fix in Kernel Git Commit caa0207 for technical details.

Detection Methods for CVE-2026-98330

Indicators of Compromise

  • Kernel oops messages referencing genlmsg_multicast_netns, nl80211_notify_wiphy, or wiphy_unregister in the call trace
  • Kernel mode fault at addr 0x30 entries in dmesg or /var/log/kern.log originating from the cfg80211 module
  • Unexpected system crashes or soft lockups coinciding with container teardown or network namespace deletion events

Detection Strategies

  • Monitor kernel ring buffer output for faults inside cfg80211 and nl80211 symbols using log aggregation.
  • Correlate namespace lifecycle events (unshare, container stop/destroy) with kernel panics on hosts carrying wireless hardware.
  • Audit kernel versions across the fleet and flag hosts running cfg80211 builds that predate commits 4635b1a, b949b27, or caa0207.

Monitoring Recommendations

  • Ingest dmesg and /var/log/kern.log into a centralized logging pipeline for pattern-based alerting on cfg80211 faults.
  • Alert on repeated allocation failure messages (page allocation failure, OOM) occurring near wireless subsystem events.
  • Track namespace create/destroy rates on hosts with Wi-Fi hardware to spot anomalous activity that could indicate exploitation attempts.

How to Mitigate CVE-2026-98330

Immediate Actions Required

  • Apply the upstream Linux kernel patches referenced in commits 4635b1a, b949b27, and caa0207 or install distribution kernel updates that include these fixes.
  • Prioritize patching hosts with wireless hardware that also run container runtimes or workloads that create and destroy network namespaces.
  • Restrict unprivileged user namespace creation on systems where it is not required to reduce the local attack surface.

Patch Information

The fix modifies cfg80211_pernet_exit() to remove interfaces that cannot be moved rather than leaving the wiphy with a dangling netns pointer. The upstream commits are available at Kernel Git Commit 4635b1a, Kernel Git Commit b949b27, and Kernel Git Commit caa0207. Rebuild and reboot hosts after applying stable kernel updates.

Workarounds

  • Unload the cfg80211 and dependent wireless modules on systems that do not require wireless networking using modprobe -r.
  • Limit the ability of unprivileged users to create network namespaces via sysctl -w kernel.unprivileged_userns_clone=0 where supported.
  • Avoid frequent namespace teardown on wireless-enabled hosts until kernel updates are deployed.
bash
# Configuration example
# Disable unprivileged user namespace creation (Debian/Ubuntu)
sysctl -w kernel.unprivileged_userns_clone=0

# Verify running kernel version
uname -r

# Check if cfg80211 is loaded and remove if unused
lsmod | grep cfg80211
modprobe -r cfg80211

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.