Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: reject out-of-range link ids in mt76_vif_link()

mt76_vif_link() indexes mvif->link[] without validating link_id, but
callers pass mvif->deflink_id / msta->deflink_id, which hold
IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added.
Since IEEE80211_MLD_MAX_NUM_LINKS is 15, that reads one element past the
end of the array, aliasing mt76_vif_data.offchannel_link.

Reachable via mt7996_set_tsf()/mt7996_offset_tsf() and
mt7996_net_fill_forward_path(). Bounds check link_id and return NULL,
matching mt7996_sta_link() and mt7996_sta_link_protected().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s mt76 driver for Wi‑Fi hardware allows an out‑of‑range array index to be used when setting the link identifier. The affected function reads past the end of the link array, accessing an adjacent data field that holds off‑channel link information. This flawed bounds check can cause the kernel to read invalid memory locations, potentially corrupting internal state or leaking sensitive information. If abused, an attacker could trigger kernel instability or gain unintended access to control‑information, resulting in a denial of service on the affected system.

Affected Systems

All Linux kernel installations that include the mt76 driver for MT76xx wireless adapters are vulnerable. The issue is present in any kernel version that ships with the unpatched driver implementation; however, specific affected versions are not enumerated in the advisory. Users of distributions that package a recent kernel with this driver should verify whether the patch has been applied, as the flaw exists in the core Wi‑Fi stack.

Risk and Exploitability

The advisory lists an EPSS score of less than 1%, indicating a low probability of exploitation at the current time, and the vulnerability is not in the CISA KEV catalog. Nonetheless, because the flaw can be triggered by calls made during normal Wi‑Fi operation, an attacker with network or physical proximity could exercise the vulnerable functions through crafted frames or device activity. The lack of a public exploit and low EPSS score suggest limited immediate risk, but mitigations should still be applied promptly, as the flaw has the potential for local privilege escalation or instability.

Generated by OpenCVE AI on September 19, 2026 at 04:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the mt76 driver patch for this vulnerability.
  • If an update is not yet available or cannot be applied, disable the affected Wi‑Fi device in the BIOS/UEFI or by setting the driver to a non‑functional mode to prevent the vulnerable code path from executing.
  • Monitor system logs for messages indicating anomalous Wi‑Fi activity or kernel crashes and verify that the issue does not recur after the applied update.

Generated by OpenCVE AI on September 19, 2026 at 04:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-129

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: reject out-of-range link ids in mt76_vif_link() mt76_vif_link() indexes mvif->link[] without validating link_id, but callers pass mvif->deflink_id / msta->deflink_id, which hold IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added. Since IEEE80211_MLD_MAX_NUM_LINKS is 15, that reads one element past the end of the array, aliasing mt76_vif_data.offchannel_link. Reachable via mt7996_set_tsf()/mt7996_offset_tsf() and mt7996_net_fill_forward_path(). Bounds check link_id and return NULL, matching mt7996_sta_link() and mt7996_sta_link_protected().
Title wifi: mt76: reject out-of-range link ids in mt76_vif_link()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:58.226Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90350

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.810

Modified: 2026-09-17T17:17:33.810

Link: CVE-2026-90350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:00:14Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-129

    Improper Validation of Array Index