← All Advisories

CVE-2026-98311

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98311

Key Details

CVECVE-2026-98311
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: don't transfer operstate before register

virt_wifi_newlink() calls netif_stacked_transfer_operstate() before

register_netdevice(). If the lower device is dormant, that queues the

new netdev on lweventlist while it is still uninitialized. If

registration fails after that, for example because of an invalid name

such as "bad/name", free_netdev() immediately frees the object. A

later linkwatch_fire_event() then use-after-frees the list entry.

Move the transfer to after netdev_upper_dev_link(), as macvlan and

ipvlan already do. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98311
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98311