CVE-2026-98073: net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
In the Linux kernel, the following vulnerability has been resolved:
net: Remove conflicting altnames for dying netns in devchangenetnamespace().
syzbot reported the warning in cfg80211pernetexit(). [0]
The repro does the following:
1. create two device in root netns and non-root netns 2. assign the same altname for the two devices 3. remove the non-root netns
Since commit 7663d522099e ("net: check for altname conflicts when changing netdev's netns"), cfg80211switchnetns() and cfg802154switchnetns() fail if initnet has a device with the conflicting altname.
defaultdeviceexitnet() had the same issue and commit d09486a04f5d ("net: fix removing a namespace with conflicting altnames") fixed it.
cfg80211pernetexit() and cfg802154pernetexit() need the same fix.
Let's generalise the fix by removing conflicting altnames for dying netns in devchangenetnamespace().
[0]: cfg80211switchnetns(rdev, &initnet) WARNING: net/wireless/core.c:1871 at cfg80211pernetexit+0xd5/0x120 net/wireless/core.c:1871, CPU#1: kworker/u8:9/1160 Modules linked in: CPU: 1 UID: 0 PID: 1160 Comm: kworker/u8:9 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026 Workqueue: netns cleanupnet RIP: 0010:cfg80211pernetexit+0xd5/0x120 net/wireless/core.c:1871 Code: e8 03 42 80 3c 20 00 74 08 4c 89 f7 e8 b4 ef 0e f7 4d 8b 36 49 81 fe 20 10 4a 90 74 12 e8 03 3d 9f f6 eb 85 e8 fc 3c 9f f6 90 <0f> 0b 90 eb cc e8 f1 3c 9f f6 eb 05 e8 ea 3c 9f f6 5b 41 5c 41 5e RSP: 0018:ffffc900057a78f0 EFLAGS: 00010293 RAX: ffffffff8b287154 RBX: ffff88807ba72780 RCX: ffff8880213e8000 RDX: 0000000000000000 RSI: 00000000ffffffef RDI: 0000000000000000 RBP: 00000000ffffffef R08: ffffffff9024cc67 R09: 0000000000000000 R10: fffff52000af4eb0 R11: fffffbfff204998d R12: dffffc0000000000 R13: ffffffff904a1080 R14: ffff888144ed0008 R15: ffff888144ed0e20 FS: 0000000000000000(0000) GS:ffff888124de6000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005642de0a8a70 CR3: 000000007a40c000 CR4: 00000000003526f0 Call Trace: <TASK> opsexitlist net/core/netnamespace.c:200 [inline] opsundolist+0x43d/0x8d0 net/core/netnamespace.c:253 cleanupnet+0x572/0x810 net/core/netnamespace.c:706 processonework kernel/workqueue.c:3387 [inline] processscheduledworks+0xc3d/0x1630 kernel/workqueue.c:3470 workerthread+0xa47/0xfb0 kernel/workqueue.c:3551 kthread+0x38b/0x480 kernel/kthread.c:436 retfromfork+0x514/0xb70 arch/x86/kernel/process.c:158 retfromforkasm+0x1a/0x30 arch/x86/entry/entry64.S:245 </TASK>
Affected Software
Event History
Frequently Asked Questions
What conditions are needed to trigger the warning?
A device in the initial network namespace and a device in a non-root network namespace must have the same alternative name. Removing the non-root namespace can then cause namespace-switch handling in cfg80211 or cfg802154 to fail because of the name conflict.
Which systems are most relevant to investigate?
Investigate Linux systems that use network namespaces and create devices with alternative names, particularly where wireless cfg80211 or IEEE 802.15.4 cfg802154 devices may be moved back to the initial namespace during namespace teardown.
How can I determine whether this has already occurred?
Check kernel logs for a warning from cfg80211_pernet_exit(), including messages referencing cfg80211_switch_netns() and a failure while removing a network namespace. The reported warning identifies net/wireless/core.c:1871.
What can be done before applying a fix?
Avoid assigning identical alternative interface names to devices in the initial and non-root network namespaces. In particular, ensure alternative names are unique before deleting a non-root namespace.