{"id":"CVE-2026-98331","summary":"wifi: mac80211: unlist vifs when their netdev is unregistered","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: unlist vifs when their netdev is unregistered\n\nmac80211 only removes vifs from the local-\u003einterfaces list when\nan interface is removed via ieee80211_if_remove(), before it\nunregisters the netdev. However, it's possible for a netdev to\nbe unregistered without going through that: When the netns that\nholds the wiphy is destroyed, the wiphy is supposed to move to\nthe init_ns, but that can run into allocation failures.\n\nThen, mac80211 has an interface listed that doesn't exist, and\nwill eventually hit\n\n  BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!\n  ...\n  _cfg80211_unregister_wdev+0x24/0x36a [cfg80211]\n  cfg80211_unregister_wdev+0x15/0x1d [cfg80211]\n  ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]\n  ieee80211_unregister_hw+0x73/0x1d1 [mac80211]\n  mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]\n\nRemove the interface from the list in -\u003endo_uninit if it's still\naround to avoid this.","modified":"2026-10-08T02:52:57.293918526Z","published":"2026-10-06T08:46:23.481Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98331.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/20a56e96a6f7b4dfbd13f8732fd2673409fc7ba0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/821bab0456dfca12acef6df702c8f2477d313227"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a22c02863439993095acd0c3db97fa53cd515f4f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b735ad1a9aca6080192c1316cf2706e5e1318762"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d45bf731ec7085d2cc2c5d179d3b3b6c743d4fb1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eee2efd82867b623982ac51925b5a1812a74c50d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98331.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98331"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"463d018323851a608eef52a9427b0585005c647f"},{"fixed":"a22c02863439993095acd0c3db97fa53cd515f4f"},{"fixed":"20a56e96a6f7b4dfbd13f8732fd2673409fc7ba0"},{"fixed":"b735ad1a9aca6080192c1316cf2706e5e1318762"},{"fixed":"d45bf731ec7085d2cc2c5d179d3b3b6c743d4fb1"},{"fixed":"821bab0456dfca12acef6df702c8f2477d313227"},{"fixed":"eee2efd82867b623982ac51925b5a1812a74c50d"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98331.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.32"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98331.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}