{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31695", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.131Z", "datePublished": "2026-05-01T13:53:36.857Z", "dateUpdated": "2026-08-05T12:24:33.507Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:33.507Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free\n\nCurrently we execute `SET_NETDEV_DEV(dev, &priv->lowerdev->dev)` for\nthe virt_wifi net devices. However, unregistering a virt_wifi device in\nnetdev_run_todo() can happen together with the device referenced by\nSET_NETDEV_DEV().\n\nIt can result in use-after-free during the ethtool operations performed\non a virt_wifi device that is currently being unregistered. Such a net\ndevice can have the `dev.parent` field pointing to the freed memory,\nbut ethnl_ops_begin() calls `pm_runtime_get_sync(dev->dev.parent)`.\n\nLet's remove SET_NETDEV_DEV for virt_wifi to avoid bugs like this:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in __pm_runtime_resume+0xe2/0xf0\n Read of size 2 at addr ffff88810cfc46f8 by task pm/606\n\n Call Trace:\n \n dump_stack_lvl+0x4d/0x70\n print_report+0x170/0x4f3\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n kasan_report+0xda/0x110\n ? __pm_runtime_resume+0xe2/0xf0\n ? __pm_runtime_resume+0xe2/0xf0\n __pm_runtime_resume+0xe2/0xf0\n ethnl_ops_begin+0x49/0x270\n ethnl_set_features+0x23c/0xab0\n ? __pfx_ethnl_set_features+0x10/0x10\n ? kvm_sched_clock_read+0x11/0x20\n ? local_clock_noinstr+0xf/0xf0\n ? local_clock+0x10/0x30\n ? kasan_save_track+0x25/0x60\n ? __kasan_kmalloc+0x7f/0x90\n ? genl_family_rcv_msg_attrs_parse.isra.0+0x150/0x2c0\n genl_family_rcv_msg_doit+0x1e7/0x2c0\n ? __pfx_genl_family_rcv_msg_doit+0x10/0x10\n ? __pfx_cred_has_capability.isra.0+0x10/0x10\n ? stack_trace_save+0x8e/0xc0\n genl_rcv_msg+0x411/0x660\n ? __pfx_genl_rcv_msg+0x10/0x10\n ? __pfx_ethnl_set_features+0x10/0x10\n netlink_rcv_skb+0x121/0x380\n ? __pfx_genl_rcv_msg+0x10/0x10\n ? __pfx_netlink_rcv_skb+0x10/0x10\n ? __pfx_down_read+0x10/0x10\n genl_rcv+0x23/0x30\n netlink_unicast+0x60f/0x830\n ? __pfx_netlink_unicast+0x10/0x10\n ? __pfx___alloc_skb+0x10/0x10\n netlink_sendmsg+0x6ea/0xbc0\n ? __pfx_netlink_sendmsg+0x10/0x10\n ? __futex_queue+0x10b/0x1f0\n ____sys_sendmsg+0x7a2/0x950\n ? copy_msghdr_from_user+0x26b/0x430\n ? __pfx_____sys_sendmsg+0x10/0x10\n ? __pfx_copy_msghdr_from_user+0x10/0x10\n ___sys_sendmsg+0xf8/0x180\n ? __pfx____sys_sendmsg+0x10/0x10\n ? __pfx_futex_wait+0x10/0x10\n ? fdget+0x2e4/0x4a0\n __sys_sendmsg+0x11f/0x1c0\n ? __pfx___sys_sendmsg+0x10/0x10\n do_syscall_64+0xe2/0x570\n ? exc_page_fault+0x66/0xb0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \n\nThis fix may be combined with another one in the ethtool subsystem:\nhttps://lore.kernel.org/all/20260322075917.254874-1-alex.popov@linux.com/T/#u" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable path is reached through local rtnetlink/generic-netlink ethtool operations on a virt_wifi netdev, not by received WiFi or network frames.\nAC:L - The attacker can control both sides of the race by issuing ethtool operations while concurrently unregistering the lower/virt_wifi devices. No external victim timing or rare condition is required.\nPR:L - The path requires CAP_NET_ADMIN, but the relevant rtnetlink and ethtool checks are namespace-capable and can be reached by an unprivileged local user in a user/network namespace.\nUI:N - No victim action is required once the attacker has local access and can send the netlink requests.\nS:U - This is standard kernel memory corruption within the same host kernel security authority, not a VM escape or cross-scope boundary violation.\nC:H - The bug is a use-after-free of the netdev parent device through pm_runtime_get_sync, and UAF memory corruption is defensibly capable of exposing kernel memory.\nI:H - The runtime PM path can operate on freed/reused memory, including atomic and lock/state updates, making kernel memory corruption and write/control-flow exploitation plausible.\nA:H - The reported failure is a KASAN slab-use-after-free in __pm_runtime_resume and can crash/oops the kernel, causing high availability impact." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/wireless/virtual/virt_wifi.c" ], "versions": [ { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "e90f3e74e1ebc26c461a74be490d322716bcdcb4", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "dcb5915696bd7b32b6404a897c24ee47cb23e772", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "d1e3aa80e6e04410ba89eaaba4441a0d749d181d", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "c5fa98842783ed227365d1303785de6a67020c8d", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "5bbadf60b121065ffb267ec92018607b9c1c7524", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "5adc01506da94dfaab76f3d1b8410a8ca7bfc59d", "status": "affected", "versionType": "git" }, { "version": "d43c65b05b848e0b2db1a6c78b02c189da3a95b5", "lessThan": "789b06f9f39cdc7e895bdab2c034e39c41c8f8d6", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/wireless/virtual/virt_wifi.c" ], "versions": [ { "version": "5.15", "status": "affected" }, { "version": "0", "lessThan": "5.15", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.203", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.168", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.134", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.81", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.22", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.12", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "5.15.203" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.1.168" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.6.134" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.12.81" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.18.22" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.19.12" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "7.0" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/e90f3e74e1ebc26c461a74be490d322716bcdcb4" }, { "url": "https://git.kernel.org/stable/c/dcb5915696bd7b32b6404a897c24ee47cb23e772" }, { "url": "https://git.kernel.org/stable/c/d1e3aa80e6e04410ba89eaaba4441a0d749d181d" }, { "url": "https://git.kernel.org/stable/c/c5fa98842783ed227365d1303785de6a67020c8d" }, { "url": "https://git.kernel.org/stable/c/5bbadf60b121065ffb267ec92018607b9c1c7524" }, { "url": "https://git.kernel.org/stable/c/5adc01506da94dfaab76f3d1b8410a8ca7bfc59d" }, { "url": "https://git.kernel.org/stable/c/789b06f9f39cdc7e895bdab2c034e39c41c8f8d6" } ], "title": "wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free", "x_generator": { "engine": "bippy-1.2.0" } } } }