Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: fix double hif2 init on the non-WED path

mt7915_pci_init_hif2() was called unconditionally and again inside the
WED-inactive branch. The helper increments the global hif_idx, writes the
PCIe RECOG_ID register and takes a get_device() reference via
mt7915_pci_get_hif2(), while removal only drops one reference. On non-WED
dual-hif hardware this double-incremented hif_idx, wrote RECOG_ID twice and
leaked a device reference. Only the call inside the WED-inactive branch is
correct; drop the unconditional one. hif2 is already initialised to NULL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Device reference leak leading to resource exhaustion
Action: Patch
AI Analysis

Impact

The issue arises when the mt7915 Wi‑Fi driver performs a double initialization of the HIF2 interface on non‑WED paths. The init function is called unconditionally and again inside a conditional block, causing the global hif_idx counter to increment twice, the PCIe RECOG_ID register to be written twice, and an extra reference to the device object to be obtained. Because the corresponding release path removes only a single reference, a reference leak occurs. Although the vulnerability is not directly exploitable via user input, the leaked reference can accumulate over time and exhaust kernel reference counts or memory, potentially destabilizing the Wi‑Fi subsystem and impacting availability.

Affected Systems

All Linux kernel builds that incorporate the mt7915 driver without the commit that fixes the double‑initialization logic are affected. The flaw resides in the mt76 driver code family and is present in any distribution kernel that has not yet applied the specific patch commit. Users should verify whether their kernel version contains the committed fix or any later kernel release that implements it.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low probability of exploitation in the wild, and the CVE is not listed in the CISA KEV catalog. The flaw requires kernel‑level execution to trigger the double initialization, making it relevant mainly to local privileged users or through a local privilege escalation vector. If successfully triggered, the resulting reference leak and duplicated register writes could degrade system stability or lead to resource exhaustion, thereby impacting availability of the Wi‑Fi subsystem.

Generated by OpenCVE AI on September 19, 2026 at 14:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the mt7915 driver patch from the Linux kernel tree.
  • Reboot the system after the kernel update so the patched driver is loaded.
  • If an immediate kernel update is not feasible, temporarily disable the wireless interface or unload the mt7915 module until a patched kernel becomes available.

Generated by OpenCVE AI on September 19, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix double hif2 init on the non-WED path mt7915_pci_init_hif2() was called unconditionally and again inside the WED-inactive branch. The helper increments the global hif_idx, writes the PCIe RECOG_ID register and takes a get_device() reference via mt7915_pci_get_hif2(), while removal only drops one reference. On non-WED dual-hif hardware this double-incremented hif_idx, wrote RECOG_ID twice and leaked a device reference. Only the call inside the WED-inactive branch is correct; drop the unconditional one. hif2 is already initialised to NULL.
Title wifi: mt76: mt7915: fix double hif2 init on the non-WED path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:00.880Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.260

Modified: 2026-09-17T17:17:34.260

Link: CVE-2026-90354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses