---
id: CVE-2026-98351
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: virt_wifi: free skb when disconnected

  When the simulated link is disconnected, virt_wifi_start_xmit() returns
  NET_XMIT_DROP without freeing the skb
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  wifi: virt_wifi: free skb when disconnected

  When the simulated link is disconnected, virt_wifi_start_xmit() returns
  NET_XMIT_DROP without freeing the skb. dev_hard_sta…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    38d3a5df85345f158f78b478b265ca906224454e
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    ee053ea35c759135460f03d1c574f4ed08de844a
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    d177eca79e1106834bc423d3969a4a2e3987996a
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    36727a702cf8e3399e3da60d0856378f6afcfb34
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    56469996c10a0240653fc00576b4d33bdfb4cc51
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    4f266738af45675faa0e8afee08c6e780afa8b06
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    46371442847a725cc0df3697fea2eba1dd54b82b
  - >-
    Linux >= c7cdba31ed8b87526db978976392802d3f93110c <
    f9edf7cf63b96d2b776fca8d258d3c5256e40c8e
  - Linux 5.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:28.437'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98351'
references:
  - url: 'https://git.kernel.org/stable/c/36727a702cf8e3399e3da60d0856378f6afcfb34'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/38d3a5df85345f158f78b478b265ca906224454e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/46371442847a725cc0df3697fea2eba1dd54b82b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4f266738af45675faa0e8afee08c6e780afa8b06'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56469996c10a0240653fc00576b4d33bdfb4cc51'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d177eca79e1106834bc423d3969a4a2e3987996a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ee053ea35c759135460f03d1c574f4ed08de844a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f9edf7cf63b96d2b776fca8d258d3c5256e40c8e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.398Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: free skb when disconnected

When the simulated link is disconnected, virt_wifi_start_xmit() returns
NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this
return value as consumed, so every packet sent while disconnected leaks its
skb.

Free the skb before returning the drop status.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
