Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed

If the WED attach for the primary PCIe function fails, the probe path
still attached wed_hif2 for the secondary function, leaving the device
in an inconsistent half-WED configuration that crashes later. The hif2
call also re-enabled hwrro_mode, which the failed primary attach had
just turned off.

Skip the hif2 WED setup when the primary WED device is not active.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via device crash
Action: Patch
AI Analysis

Impact

In the Linux kernel’s mt76 driver for the mt7996 chipset, if the primary PCIe function fails to attach a WED device, the probe path may still proceed to attach the WED for the secondary function. This results in a half‑configured device that later crashes. The secondary attach also inadvertently re‑enables hwrro_mode, reversing protection that the primary failure had disabled, further destabilizing the hardware and software stack.

Affected Systems

All Linux distributions that ship the mt76 driver containing an mt7996 implementation are affected. Since no specific kernel versions are listed, any kernel that includes this code path should be considered potentially impacted.

Risk and Exploitability

Based on the description, it is inferred that the vulnerability can be exploited by an attacker with local or privileged access who can trigger the driver’s probe path. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of current exploitation. The absence of a CVSS score limits a precise severity assessment, but the EPSS data and the potential for a device crash suggest a significant denial‑of‑service risk.

Generated by OpenCVE AI on September 19, 2026 at 14:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the mt76 mt7996 driver fix
  • If a kernel upgrade is not feasible, unload or blacklist the mt76 module until an updated kernel is available
  • Deploy monitoring to detect unexpected device crashes and implement rapid recovery or fallback drivers

Generated by OpenCVE AI on September 19, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-749

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed If the WED attach for the primary PCIe function fails, the probe path still attached wed_hif2 for the secondary function, leaving the device in an inconsistent half-WED configuration that crashes later. The hif2 call also re-enabled hwrro_mode, which the failed primary attach had just turned off. Skip the hif2 WED setup when the primary WED device is not active.
Title wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:58.905Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90351

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.913

Modified: 2026-09-17T17:17:33.913

Link: CVE-2026-90351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function