Linux Kernel Vulnerability in virt_wifi Component Leading to skb Memory Leak
CVE-2026-98351

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98351?

A vulnerability in the Linux kernel's virt_wifi component leads to a memory leak issue when the simulated link is disconnected. Specifically, the function virt_wifi_start_xmit() returns NET_XMIT_DROP without properly freeing the socket buffer (skb). Consequently, dev_hard_start_xmit() misinterprets this return status as a consumed packet, allowing any packet sent while disconnected to cause a leak of its skb. To mitigate this issue, it is essential to free the skb before returning a drop status, ensuring system stability and resource integrity.

Affected Version(s)

Linux c7cdba31ed8b87526db978976392802d3f93110c < 38d3a5df85345f158f78b478b265ca906224454e

Linux c7cdba31ed8b87526db978976392802d3f93110c

Linux c7cdba31ed8b87526db978976392802d3f93110c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.