Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV

When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two
bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but
MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a
near-maximum beacon template the extra 8 bytes could push the offload
command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic().
Reserve room for both countdown TLVs.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Apply patch
AI Analysis

Impact

A buffer reservation bug in the Linux kernel wireless driver for the MT7996 chipset causes an out‑of‑bounds write when a CA‑shutdown (CSA) beacon countdown is active. The driver emits two countdown TLV entries but reserves space for only one, allowing an eight‑byte overflow that can push the offload command past the maximum allowed size and trigger an skb_over_panic(). This defect results in an operating‑system crash, leaving the affected system in an unreachable state until rebooted. Based on the description, it is inferred that the likely attack vector is an attacker who can instruct the wireless interface to emit a beacon with MBSSID enabled and a near‑maximum beacon template via crafted wireless frames.

Affected Systems

The flaw resides in the core Linux kernel, specifically in the mt76/mt7996 wireless module. All kernel versions that compile this driver without the patch are potentially vulnerable; no explicit affected range is supplied, so any kernel build that contains the unpatched code is at risk.

Risk and Exploitability

The EPSS score is lower than 1 % and the flaw is not listed in the CISA KEV catalog, indicating a low current exploitation probability. Based on the description, it is inferred that the likely attack vector is an attacker who can instruct the wireless interface to emit a beacon with MBSSID enabled and a near‑maximum beacon template via crafted wireless frames. The impact is a denial of service by causing a kernel panic. The lack of a CVSS score in the data set precludes a precise severity figure, but the failure mode suggests a high‑severity outcome locally. The official solution is to apply the kernel patch that reserves space for both countdown TLVs, as referenced in the provided kernel commit URLs.

Generated by OpenCVE AI on September 19, 2026 at 14:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that reserves space for both CSA countdown TLVs in the mt7996 driver
  • If a patch cannot be applied immediately, disable MBSSID or reduce beacon size on affected interfaces to prevent the overflow from occurring
  • Upgrade the Linux kernel to a release that includes the mt7996 driver fix

Generated by OpenCVE AI on September 19, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a near-maximum beacon template the extra 8 bytes could push the offload command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic(). Reserve room for both countdown TLVs.
Title wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:08.785Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:35.700

Modified: 2026-09-17T17:17:35.700

Link: CVE-2026-90366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer