Local memory corruption vulnerability in Linux kernel wireless subsystem
CVE-2026-98341

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98341?

The Linux kernel's wireless subsystem experiences a local memory corruption vulnerability due to improper handling of driver-owned scan requests. When an interface goes down while a scan is in progress, the cfg80211 framework incorrectly frees the scan request, which can lead to a use-after-free (UAF) situation. This occurs because the driver may continue to believe it owns the request, resulting in unintended consequences. The fix ensures that the system tracks the ownership status of scan requests and appropriately manages memory freeing upon completion.

Affected Version(s)

Linux 4a58e7c38443154fce1b47910e1a9184f65c5d72

Linux 4a58e7c38443154fce1b47910e1a9184f65c5d72

Linux 4a58e7c38443154fce1b47910e1a9184f65c5d72

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.