Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: clear stale link state on full reset

After a full chip reset, mac80211 reconfig replays interface, link and
channel context setup. mt7996_vif_link_add() short-circuits when the
link_id is still marked in mvif->valid_links, a state introduced for
postponing link teardown to interface removal. The reset path frees the
link structures without clearing those bits, so the replayed setup never
re-creates dev_info/bss_info/STA records in the restarted firmware and
never re-registers the link wcid, leaving the device inoperative.

The reset path also leaks every allocated MLD index: per-link indices
and the per-vif group/remap indices are re-allocated from scratch during
reconfig, but the old bits stay set in the masks, so repeated full
resets exhaust the index space.

Clear valid_links in the reset vif iterator and reset the MLD index
masks alongside the existing omac_mask clearing.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (WiFi interface)
Action: Apply patch
AI Analysis

Impact

After a full chip reset, the Linux kernel driver for mt76/mt7996 fails to clear an internal flag that marks a link as valid. The replayed Wi‑Fi configuration never recreates critical data structures, so the restarted firmware cannot register the link. The device remains inoperative and a reset sequence that repeats the bug repeatedly drives the firmware into a state where it runs out of index space for multi‑link and virtual‑interface identifiers. The result is a denial of service that can be experienced immediately after a reset or after multiple full‑reset events.

Affected Systems

The affected systems are standard Linux kernel installations that use the mt76 Wi‑Fi driver for Mediatek's MT7996 chip. No product version list is currently published, so any kernel version that includes mt76/mt7996 code may be vulnerable until the race condition is eliminated. There is no vendor‑specific packaging information beyond the generic Linux kernel.

Risk and Exploitability

The EPSS score is below one percent and the vulnerability is not listed in the CISA KEV catalogue, indicating that the likelihood of widespread exploitation is low. The CVSS score is unavailable, but the impact is limited to devices that perform a full chip reset – an operation typically reserved for system boot or reset events and not normally exposed to remote attackers. Consequently, the overall risk is moderate: potential denial of service for Wi‑Fi clients that rely on the affected device, but the attack surface is constrained to privileged users or firmware-level interactions. The denial of service comes from state corruption and resource exhaustion in the driver, rather than remote code execution.

Generated by OpenCVE AI on September 19, 2026 at 04:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the mt76/mt7996 fix.
  • If an immediate kernel upgrade is not feasible, disable or limit full‑chip resets for the Wi‑Fi interface, and avoid repeated reset cycles that could exhaust link index space.
  • Monitor system logs for repeated failures to register Wi‑Fi links and perform manual reinitialisation or a device reboot if the interface becomes inoperative.

Generated by OpenCVE AI on September 19, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-230
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: clear stale link state on full reset After a full chip reset, mac80211 reconfig replays interface, link and channel context setup. mt7996_vif_link_add() short-circuits when the link_id is still marked in mvif->valid_links, a state introduced for postponing link teardown to interface removal. The reset path frees the link structures without clearing those bits, so the replayed setup never re-creates dev_info/bss_info/STA records in the restarted firmware and never re-registers the link wcid, leaving the device inoperative. The reset path also leaks every allocated MLD index: per-link indices and the per-vif group/remap indices are re-allocated from scratch during reconfig, but the old bits stay set in the masks, so repeated full resets exhaust the index space. Clear valid_links in the reset vif iterator and reset the MLD index masks alongside the existing omac_mask clearing.
Title wifi: mt76: mt7996: clear stale link state on full reset
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:01.543Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.380

Modified: 2026-09-17T17:17:34.380

Link: CVE-2026-90355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:30:16Z

Weaknesses
  • CWE-230

    Improper Handling of Missing Values

  • CWE-665

    Improper Initialization