{"id":"CVE-2026-98311","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don't transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don't transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice(). If the lower device…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= c7cdba31ed8b87526db978976392802d3f93110c < ee9ea1afd6990def51d52b3a0aecd5cfcc951da0","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < 9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < f9526054c2b2cace5916b7225603d008834ec011","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < e8304e25c6dabb8accf38b807969438d0ce84fd7","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < ca49763c42c1089d654bf11b037980a9ede3772c","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < 293c56a66510bb7de073a1aba388e38abddff1fb","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < b808a9af5fd21f9c68b0d024eda7535b5dce6a4e","Linux >= c7cdba31ed8b87526db978976392802d3f93110c < e5c8d7acd31b27057ea42cd405d0b3ece097bc89","Linux 5.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:22.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98311","references":[{"url":"https://git.kernel.org/stable/c/293c56a66510bb7de073a1aba388e38abddff1fb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ce26201f6dedf3fa02b97da8c67ee6f6c5f7225","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b808a9af5fd21f9c68b0d024eda7535b5dce6a4e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca49763c42c1089d654bf11b037980a9ede3772c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5c8d7acd31b27057ea42cd405d0b3ece097bc89","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8304e25c6dabb8accf38b807969438d0ce84fd7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee9ea1afd6990def51d52b3a0aecd5cfcc951da0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9526054c2b2cace5916b7225603d008834ec011","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.410Z","slug":"CVE-2026-98311","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: don't transfer operstate before register\n\nvirt_wifi_newlink() calls netif_stacked_transfer_operstate() before\nregister_netdevice(). If the lower device is dormant, that queues the\nnew netdev on lweventlist while it is still uninitialized. If\nregistration fails after that, for example because of an invalid name\nsuch as \"bad/name\", free_netdev() immediately frees the object. A\nlater linkwatch_fire_event() then use-after-frees the list entry.\n\nMove the transfer to after netdev_upper_dev_link(), as macvlan and\nipvlan already do.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}