Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement

The flow is added to dev->twt_list before sending the agreement to the
firmware, but the error path leaves it linked while flowid_mask is
never set. The flow slot can then be reused and memset while still on
the list, corrupting twt_list, and station removal leaves a dangling
entry behind that mt7915_mac_twt_sched_list_add() later walks.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially enabling arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Linux wifi driver mt76’s mt7915 module. A TWT flow is appended to the device's list before the firmware agreement is sent. When the MCU rejects the agreement, the error path fails to clear or unlink the flow but leaves it in the list. The flow slot may then be reused and overwritten while still on the list, corrupting the TWT list structure. This memory corruption can destabilize the kernel and, if exploited, could allow an attacker to execute arbitrary code with kernel privileges. The flaw is a classic instance of improper handling of list nodes, leading to list corruption.

Affected Systems

All Linux kernel builds that ship the mt76/mt7915 wifi driver before the patch included in commit c09d1b15 are affected. The specific kernel version is not listed in the data, so any distribution using a kernel containing the unpatched driver must be considered vulnerable until the fix is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need local access to the device or the ability to send crafted TWT requests over WiFi, implying that the attack vector is local or possibly remote if the driver is exposed to network traffic. The exploit would require triggering the error path and manipulating the TWT flow, which is feasible given the driver’s behavior described in the commit messages.

Generated by OpenCVE AI on September 19, 2026 at 15:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the mt76/mt7915 TWT unlink fix (commit c09d1b15).
  • Reboot the system to ensure the updated kernel is running.
  • Monitor kernel logs for TWT-related errors to confirm that the list corruption no longer occurs.

Generated by OpenCVE AI on September 19, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement The flow is added to dev->twt_list before sending the agreement to the firmware, but the error path leaves it linked while flowid_mask is never set. The flow slot can then be reused and memset while still on the list, corrupting twt_list, and station removal leaves a dangling entry behind that mt7915_mac_twt_sched_list_add() later walks.
Title wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:49.445Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90357

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.590

Modified: 2026-09-18T18:17:55.160

Link: CVE-2026-90357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses