{"id":"AZL-106347","summary":"CVE-2026-98331 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: unlist vifs when their netdev is unregistered\n\nmac80211 only removes vifs from the local-\u003einterfaces list when\nan interface is removed via ieee80211_if_remove(), before it\nunregisters the netdev. However, it's possible for a netdev to\nbe unregistered without going through that: When the netns that\nholds the wiphy is destroyed, the wiphy is supposed to move to\nthe init_ns, but that can run into allocation failures.\n\nThen, mac80211 has an interface listed that doesn't exist, and\nwill eventually hit\n\n  BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!\n  ...\n  _cfg80211_unregister_wdev+0x24/0x36a [cfg80211]\n  cfg80211_unregister_wdev+0x15/0x1d [cfg80211]\n  ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]\n  ieee80211_unregister_hw+0x73/0x1d1 [mac80211]\n  mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]\n\nRemove the interface from the list in -\u003endo_uninit if it's still\naround to avoid this.","modified":"2026-10-07T14:17:02.178204349Z","published":"2026-10-06T09:18:25Z","upstream":["CVE-2026-98331"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98331"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106347.json"}}],"schema_version":"1.9.0"}