Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER

mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs
before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain
kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the
same worker and the MT76_RESET bit under the mutex. An L1 SER racing a
channel switch could therefore have the worker unparked and MT76_RESET
cleared while the reset path resets the DMA rings, corrupting descriptors
or tokens. Take the mutex before disabling the worker, as mt7915 does.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s mt76 Wi‑Fi driver, specifically the mt7996 sub‑driver, is a race condition that occurs when the driver disables the transmit worker during a software error recovery (SER). If a channel change is initiated while the reset routine holds the worker in a parked state, the worker can be unparked and the MT76_RESET flag cleared after the DMA ring reset. This race can corrupt DMA rings and other driver descriptors, potentially leading to kernel data corruption or a system crash.

Affected Systems

The flaw affects Linux kernels that ship with the mt76 driver for mt7996 hardware. The affected products are not limited to a specific vendor; any distribution or custom kernel that includes the mt76/mt7996 driver code is potentially vulnerable. No specific version ranges are listed in the CNA data, so all kernel versions containing the unpatched mt76 code should be considered at risk.

Risk and Exploitability

The CVSS base score is 8.8, indicating a high severity threat. The EPSS score is reported as less than 1 percent, implying a low probability that the vulnerability has been actively exploited. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is local, requiring the attacker to trigger a channel switch during a reset sequence (e.g., through malformed firmware or driver use). Because the condition involves race between kernel threads, it is difficult to reproduce reliably, further lowering the exploitability risk.

Generated by OpenCVE AI on September 19, 2026 at 15:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the mt76 driver patch for mt7996.
  • If an immediate kernel upgrade is not possible, disable Wi‑Fi interfaces or prevent firmware from initiating channel switches until the patch is available.
  • For distributions that allow, replace the mt76 module with an updated version from upstream or a vendor‑supplied patch that locks the worker before disabling it during reset.

Generated by OpenCVE AI on September 19, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the same worker and the MT76_RESET bit under the mutex. An L1 SER racing a channel switch could therefore have the worker unparked and MT76_RESET cleared while the reset path resets the DMA rings, corrupting descriptors or tokens. Take the mutex before disabling the worker, as mt7915 does.
Title wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:51.905Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90367

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:35.813

Modified: 2026-09-18T18:17:55.483

Link: CVE-2026-90367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:30:16Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')