Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: release hif2 reference on probe IRQ failure

The hif2 reference obtained by mt7915_pci_init_hif2() is only released on
error paths that key off dev->hif2, which is not assigned until after the
IRQ setup. If pci_alloc_irq_vectors() or the primary devm_request_irq()
fails, the reference leaks. Drop it explicitly on those paths via
mt7915_put_hif2().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak / Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs when the Wi‑Fi driver mt7915 fails to release a reference to the hif2 structure during IRQ initialization. The reference is only properly released on certain error paths that rely on a device field that is not yet set, causing the reference to leak when pci_alloc_irq_vectors() or devm_request_irq() fails. The leak can create a resource exhaustion problem and potentially destabilize the kernel, but it does not allow arbitrary code execution or privilege escalation.

Affected Systems

The affected product is the Linux kernel, specifically those releases that include the mt76 mt7915 Wi‑Fi driver before the fix was applied. No exact version range is provided, so any system running an unpatched kernel that incorporates this driver could be impacted.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of public exploitation. The flaw requires the driver to be probed, which typically occurs during system boot or when enabling Wi‑Fi, and therefore is a local privilege requirement. The impact is limited to resource exhaustion and potential denial of service rather than remote code execution or data breach.

Generated by OpenCVE AI on September 19, 2026 at 04:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the commit that releases the hif2 reference on probe IRQ failure; the related patches are available at the provided git kernel URLs.
  • Reboot the system after the kernel update to ensure the driver is reloaded in its fixed state.
  • If an immediate kernel update is not possible, temporarily disable the mt7915 Wi‑Fi driver or turn off Wi‑Fi until the kernel can be upgraded.

Generated by OpenCVE AI on September 19, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-762

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: release hif2 reference on probe IRQ failure The hif2 reference obtained by mt7915_pci_init_hif2() is only released on error paths that key off dev->hif2, which is not assigned until after the IRQ setup. If pci_alloc_irq_vectors() or the primary devm_request_irq() fails, the reference leaks. Drop it explicitly on those paths via mt7915_put_hif2().
Title wifi: mt76: mt7915: release hif2 reference on probe IRQ failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:59.557Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.013

Modified: 2026-09-17T17:17:34.013

Link: CVE-2026-90352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:15:10Z

Weaknesses
  • CWE-762

    Mismatched Memory Management Routines