Skip to main content
Vulnerability Database/CVE-2026-98351

CVE-2026-98351: Linux Kernel virt_wifi Info Disclosure

CVE-2026-98351 is an information disclosure flaw in Linux kernel virt_wifi that causes memory leaks when packets are sent while disconnected. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-98351 Overview

CVE-2026-98351 is a memory leak vulnerability in the Linux kernel's virt_wifi driver. The virt_wifi_start_xmit() function returns NET_XMIT_DROP without freeing the socket buffer (skb) when the simulated wireless link is in a disconnected state. Because dev_hard_start_xmit() treats this return value as consumed, every packet transmitted while the virtual interface is disconnected leaks its associated skb. Sustained transmission against a disconnected virt_wifi interface can exhaust kernel memory over time.

Critical Impact

Repeated packet transmission over a disconnected virt_wifi link leaks kernel socket buffers, enabling gradual memory exhaustion and potential denial of service.

Affected Products

  • Linux kernel versions containing the virt_wifi driver prior to the fix commits
  • Distributions shipping unpatched stable kernels referenced in the upstream commit series
  • Systems using virt_wifi for testing, virtualization, or wireless simulation workflows

Discovery Timeline

  • 2026-10-06 - CVE-2026-98351 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-98351

Vulnerability Analysis

The virt_wifi driver provides a simulated wireless network device used primarily for testing and virtualized environments. The transmit path, implemented in virt_wifi_start_xmit(), decides whether to forward the packet based on the connection state of the simulated link. When the link is disconnected, the function short-circuits and returns NET_XMIT_DROP.

The Linux networking stack treats NET_XMIT_DROP returned from a device's ndo_start_xmit callback as a signal that the driver has taken ownership of the skb. The caller dev_hard_start_xmit() therefore does not free the buffer. Because the driver neither queued the skb nor called kfree_skb() before returning, each dropped packet leaks the full buffer allocation.

The fix frees the skb prior to returning the drop status, aligning the driver with kernel networking contract expectations.

Root Cause

The root cause is an unreleased resource on an error path [CWE-401]. The driver returned a status that transfers buffer ownership to the driver without executing the corresponding kfree_skb() call, leaving the allocation stranded in kernel memory.

Attack Vector

Exploitation requires local access to a system with a virt_wifi interface in a disconnected state. Any process able to transmit packets through the interface can trigger buffer accumulation. Sustained traffic produces continuous kernel memory consumption that can degrade system stability and eventually lead to denial of service through memory exhaustion.

No verified public exploit code is available. See the upstream commits for the exact patch content: Kernel Git Commit 4f26673 and Kernel Git Commit ee053ea.

Detection Methods for CVE-2026-98351

Indicators of Compromise

  • Steadily increasing Slab or SUnreclaim values in /proc/meminfo on hosts with active virt_wifi interfaces
  • Growing skbuff_head_cache or skbuff_fclone_cache counts reported by slabtop without corresponding reclamation
  • virt_wifi interface present with operational state down while packet transmission counters continue to increment

Detection Strategies

  • Audit running kernel versions across the fleet and compare against the fixed stable releases referenced in the upstream commit series
  • Correlate kernel slab growth with transmit activity on virtual wireless interfaces using eBPF or perf tracing on virt_wifi_start_xmit
  • Monitor /sys/class/net/<virt_wifi_if>/statistics/tx_dropped for sustained increases while the link is disconnected

Monitoring Recommendations

  • Alert on unexpected kernel memory growth on hosts that load the virt_wifi module
  • Track module load events for virt_wifi through audit rules and inventory which workloads require it
  • Baseline per-host skbuff cache allocations and alert on deviations exceeding normal operational variance

How to Mitigate CVE-2026-98351

Immediate Actions Required

  • Upgrade affected systems to a Linux stable kernel release that includes the fix commits listed in the NVD advisory
  • Unload the virt_wifi module on hosts that do not require it using modprobe -r virt_wifi
  • Restart long-running hosts that have accumulated leaked skb allocations to reclaim kernel memory

Patch Information

The fix was committed to the upstream Linux kernel and backported across stable branches. Reference the upstream commits for the exact source change: Kernel Git Commit 36727a7, Kernel Git Commit 38d3a5d, Kernel Git Commit 4637144, Kernel Git Commit 4f26673, Kernel Git Commit 5646999, Kernel Git Commit d177eca, Kernel Git Commit ee053ea, and Kernel Git Commit f9edf7c. Apply vendor-supplied kernel updates once distributions publish backported packages.

Workarounds

  • Blacklist the virt_wifi module on systems where it is not operationally required
  • Keep simulated virt_wifi links in a connected state during testing to avoid traversing the leaking code path
  • Avoid generating sustained transmit traffic over a disconnected virt_wifi interface pending patch deployment
bash
# Prevent virt_wifi from loading until the host is patched
echo 'blacklist virt_wifi' | sudo tee /etc/modprobe.d/blacklist-virt_wifi.conf
sudo modprobe -r virt_wifi

# Verify current kernel version against fixed stable releases
uname -r

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.