KernelScan.io

HIGH Introduced in 3.14

cfg80211 ScanRequest UAF

CVE-2026-98341

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: don't free driver-owned scan requests When an interface goes down while a scan is running, cfg80211 completes the scan towards userspace and frees the scan request. However, the driver can be convinced that it owns the request, since the cancellation is (intended to be) asynchronous. The WARN_ON() in the netdev notifier was meant to catch this, but it's not actually avoidable, so it triggers and we get a UAF in scan_done(). There doesn't seem to be a great way around it, so just track that the driver is still convinced it owns the request, and then just free it on completion if it was already cancelled. Also remove the warnings since they can trigger in the intended architecture.

02

Engine v0.7.0

Risk summary

A local attacker with CAP_NET_ADMIN on a system with WiFi hardware can trigger a use-after-free by bringing a wireless interface down while a scan is in progress. The race condition between cfg80211's scan cleanup and the driver's asynchronous scan completion leads to kernel memory corruption, potentially enabling privilege escalation or denial of service.

Affectednet/wireless/scan.c (cfg80211 wireless subsystem)

Vulnerability analysis

When a wireless interface is taken down while a scan is still running, the wireless configuration layer completes the scan toward userspace and immediately frees the scan request. However, the driver may still believe it owns that request because scan cancellation is intentionally asynchronous. When the driver later reports scan completion, it accesses the already-freed request, causing a use-after-free. The fix tracks whether the driver still holds ownership of the request; if the configuration layer wants to clean up while the driver still owns it, the request is marked stale rather than freed, and the actual free is deferred until the driver reports completion. This vulnerability is reachable by any local user who can trigger a WiFi scan and bring the interface down, which requires CAP_NET_ADMIN obtainable through user namespaces on systems with WiFi hardware present.

03

BranchIntroducedFixed inPatch commit
6.183.146.18.54e8c75736cfd0
7.23.147.2.8cf6da29d1799
mainline3.147.3-rc4dab68a74e90b