Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset

mt7996_mac_reset_vif_iter() queues non-default vif links for kfree_rcu
while dev->wcid[] still holds pointers to the wcid embedded in each
freed link; mt76_reset_device() then dereferences those entries and
runs mt76_wcid_cleanup() on them. If a grace period elapses in between,
the cleanup operates on freed memory.

Run mt76_reset_device() first, so the wcid entries are cleaned up and
cleared while the links are still valid.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption (use‑after‑free) potentially leading to kernel crash or arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from the mt76 driver for the mt7996 Wi‑Fi chipset in the Linux kernel. During a full reset the driver queues non‑default virtual interface links for delayed freeing while the wireless client ID array still contains pointers to the data embedded in those links. A subsequent reset routine dereferences those stale pointers and performs cleanup on memory that may have already been reclaimed, creating a use‑after‑free condition that can corrupt kernel memory. If an attacker can cause a reset sequence after the grace period, they may be able to trigger a kernel crash or run arbitrary code with kernel privileges.

Affected Systems

This flaw affects the Linux kernel, specifically builds that include the mt76 driver used for mt7996 Wi‑Fi chips. No specific kernel versions are listed in the data, so the issue may exist in any open‑source distribution that compiles the current driver source.

Risk and Exploitability

The attack vector is likely local or remote control of the Wi‑Fi interface that can trigger full resets; however the data does not provide explicit details, so this is inferred. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA KEV, indicating low to moderate exploitation likelihood. Nevertheless, because the flaw can corrupt kernel memory, it is considered a high severity issue that could allow privilege escalation or denial of service if an attacker gains the ability to influence device reset operations.

Generated by OpenCVE AI on September 19, 2026 at 04:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the mt76 driver patch that performs the reset in the correct order.
  • If a kernel upgrade is not yet available, avoid triggering full device resets and use alternative reset procedures until the fix is applied.
  • Implement monitoring for kernel panics or crashes related to the Wi‑Fi driver and isolate affected hardware when possible.

Generated by OpenCVE AI on September 19, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset mt7996_mac_reset_vif_iter() queues non-default vif links for kfree_rcu while dev->wcid[] still holds pointers to the wcid embedded in each freed link; mt76_reset_device() then dereferences those entries and runs mt76_wcid_cleanup() on them. If a grace period elapses in between, the cleanup operates on freed memory. Run mt76_reset_device() first, so the wcid entries are cleaned up and cleared while the links are still valid.
Title wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:02.189Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.480

Modified: 2026-09-17T17:17:34.480

Link: CVE-2026-90356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:30:16Z

Weaknesses