Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98311— wifi: virt_wifi: don't transfer operstate before register

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: wifi: virt_wifi:不要在注册前传输操作状态 在调用 之前调用了 。如果底层设备处于休眠状态,这会将新的网络设备排队到 ,而此时该设备仍处于未初始化状态。如果随后的注册失败(例如,因为名称无效,如 "bad/name"), 会立即释放该对象。随后 会对该链表条目造成使用后释放(use-after-free)漏洞。 将操作状态的转移移至 之后进行,与 macvlan 和 ipvlan 的处理方式保持一致。

CVSS 7.8 · High EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1206

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux c7cdba31ed8b87526db978976392802d3f93110c< ee9ea1afd6990def51d52b3a0aecd5cfcc951da0 affected
c7cdba31ed8b87526db978976392802d3f93110c< 9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225 affected
c7cdba31ed8b87526db978976392802d3f93110c< f9526054c2b2cace5916b7225603d008834ec011 affected
c7cdba31ed8b87526db978976392802d3f93110c< e8304e25c6dabb8accf38b807969438d0ce84fd7 affected
c7cdba31ed8b87526db978976392802d3f93110c< ca49763c42c1089d654bf11b037980a9ede3772c affected
c7cdba31ed8b87526db978976392802d3f93110c< 293c56a66510bb7de073a1aba388e38abddff1fb affected
c7cdba31ed8b87526db978976392802d3f93110c< b808a9af5fd21f9c68b0d024eda7535b5dce6a4e affected
c7cdba31ed8b87526db978976392802d3f93110c< e5c8d7acd31b27057ea42cd405d0b3ece097bc89 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98311

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wifi: virt_wifi: don't transfer operstate before register
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: don't transfer operstate before register virt_wifi_newlink() calls netif_stacked_transfer_operstate() before register_netdevice(). If the lower device is dormant, that queues the new netdev on lweventlist while it is still uninitialized. If registration fails after that, for example because of an invalid name such as "bad/name", free_netdev() immediately frees the object. A later linkwatch_fire_event() then use-after-frees the list entry. Move the transfer to after netdev_upper_dev_link(), as macvlan and ipvlan already do.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c7cdba31ed8b87526db978976392802d3f93110c ~ ee9ea1afd6990def51d52b3a0aecd5cfcc951da0 -
Linux Linux 5.0 -

II. Public POCs for CVE-2026-98311

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98311

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98311 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98311

No comments yet


Leave a comment