Skip to main content
Vulnerability Database/CVE-2026-98331

CVE-2026-98331: Linux Kernel Privilege Escalation Vulnerability

CVE-2026-98331 is a privilege escalation flaw in the Linux kernel mac80211 subsystem that occurs when network interfaces are not properly removed from interface lists during netdev unregistration. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-98331 Overview

CVE-2026-98331 is a Linux kernel vulnerability in the mac80211 wireless subsystem. The flaw occurs when a virtual interface (vif) netdev is unregistered without being removed through the expected ieee80211_if_remove() path. When a network namespace holding a wiphy is destroyed, the wiphy should migrate to init_ns, but allocation failures during this transition can leave mac80211 tracking an interface that no longer exists. Subsequent cleanup triggers a BUG assertion in wiphy_to_rdev(), destabilizing the kernel.

Critical Impact

Local attackers with the ability to trigger namespace destruction under memory pressure can cause kernel crashes affecting system availability and potentially corrupting kernel state.

Affected Products

  • Linux kernel versions containing the mac80211 wireless subsystem prior to the fix commits
  • Distributions shipping affected stable kernel branches referenced in the kernel.org commits
  • Systems using mac80211_hwsim and other drivers backed by mac80211

Discovery Timeline

  • 2026-10-06 - CVE-2026-98331 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98331

Vulnerability Analysis

The vulnerability resides in how mac80211 manages its local->interfaces list. mac80211 removes virtual interfaces from this list exclusively through ieee80211_if_remove(), which executes before the netdev is unregistered. The subsystem assumes this is the only path by which an interface can disappear.

That assumption breaks when a network namespace owning the wiphy is destroyed. The kernel attempts to move the wiphy back to init_ns, but this operation can fail if memory allocations fail. When migration fails, the netdev is unregistered directly, bypassing ieee80211_if_remove(). The result is a stale entry in local->interfaces referencing a destroyed interface.

Subsequent teardown paths such as ieee80211_remove_interfaces() and ieee80211_unregister_hw() iterate this list and call cfg80211_unregister_wdev(), which invokes wiphy_to_rdev() on the dangling pointer. The function hits a BUG assertion at net/wireless/core.h:141, panicking the kernel.

Root Cause

The root cause is an incomplete cleanup contract between the netdev lifecycle and the mac80211 interface tracking list. The subsystem lacks a handler in ->ndo_uninit to detach interfaces when they are unregistered outside the standard removal path.

Attack Vector

Exploitation requires local access with privileges to create and destroy network namespaces containing wireless devices. An attacker induces memory pressure to force the wiphy migration to fail during namespace teardown. The condition is race-sensitive and depends on allocator behavior, making reliable exploitation difficult but feasible on constrained systems.

The fix removes the interface from local->interfaces inside the ->ndo_uninit callback if it has not already been detached. See the Linux Kernel Commit 20a56e96 and Linux Kernel Commit d45bf731 for the upstream patches.

Detection Methods for CVE-2026-98331

Indicators of Compromise

  • Kernel panic messages referencing BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()
  • Stack traces containing _cfg80211_unregister_wdev, ieee80211_remove_interfaces, or ieee80211_unregister_hw
  • Unexpected crashes during network namespace teardown on hosts with wireless or mac80211_hwsim devices

Detection Strategies

  • Monitor dmesg and /var/log/kern.log for the specific wiphy_to_rdev() assertion failure
  • Correlate kernel oops events with processes creating or destroying network namespaces that hold wireless devices
  • Track installed kernel versions across the fleet to identify hosts still running unpatched builds

Monitoring Recommendations

  • Forward kernel logs to a centralized SIEM and alert on BUG: assertions in the cfg80211 or mac80211 subsystems
  • Baseline normal namespace creation and destruction behavior to flag anomalous patterns from unprivileged workloads
  • Audit containers and sandboxes with CAP_NET_ADMIN or namespace creation privileges that interact with wireless drivers

How to Mitigate CVE-2026-98331

Immediate Actions Required

  • Apply the upstream kernel patches referenced in the kernel.org stable commits as soon as distribution updates are available
  • Inventory systems running mac80211_hwsim in test, CI, or virtualization environments and prioritize those for patching
  • Restrict unprivileged user namespace creation on multi-tenant systems where wireless subsystems are loaded

Patch Information

The fix was committed across multiple stable branches. Relevant commits include Linux Kernel Commit 20a56e96, Linux Kernel Commit 821bab04, Linux Kernel Commit a22c0286, Linux Kernel Commit b735ad1a, Linux Kernel Commit d45bf731, and Linux Kernel Commit eee2efd8.

Workarounds

  • Unload mac80211_hwsim and other mac80211-backed drivers on hosts that do not require wireless functionality
  • Disable the ability for untrusted users to create network namespaces by setting kernel.unprivileged_userns_clone=0 where supported
  • Apply memory limits on untrusted workloads to reduce the likelihood of triggering the allocation failure path
bash
# Disable unprivileged user namespaces to limit attack surface
sysctl -w kernel.unprivileged_userns_clone=0

# Remove mac80211_hwsim if not required
modprobe -r mac80211_hwsim
echo 'blacklist mac80211_hwsim' > /etc/modprobe.d/blacklist-hwsim.conf

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.