Network Namespace Vulnerability in Linux Kernel Affecting Multiple Products
CVE-2026-98330
What is CVE-2026-98330?
This vulnerability in the Linux kernel's cfg80211 subsystem occurs during the destruction of a network namespace. Specifically, when attempting to move a wiphy interface back to the initial namespace, potential errors during memory allocation can leave the interface associated with a dangling pointer. As a result, this could lead to unexpected kernel behavior and system instability. The proposed fix involves ensuring that interfaces which cannot be moved are removed, preventing further complications and maintaining proper management of network resources. For detailed patches related to this vulnerability, refer to the Linux kernel's commit history.
Affected Version(s)
Linux 463d018323851a608eef52a9427b0585005c647f
Linux 463d018323851a608eef52a9427b0585005c647f
Linux 463d018323851a608eef52a9427b0585005c647f < 4635b1a1c1d693178a537446a6e09963f0fdae52