Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: unwind state on add_interface failure

When mt76_wcid_alloc() fails, mt7915_add_interface() returned without
clearing the vif_mask/omac_mask bits it had already set, without removing
the firmware dev info added earlier, and without clearing a monitor_vif
pointer to the vif mac80211 is about to free. mac80211 does not call
remove_interface() for a failed add, so the indices and firmware dev
entry leaked permanently and testmode could dereference the stale
monitor_vif. Add a proper error unwind.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in the Linux kernel wireless driver
Action: Immediate Patch
AI Analysis

Impact

When the mt7915 driver attempts to add a wireless interface, a failure in the internal allocation routine leaves stale state in kernel data structures. The driver does not clear the vif_mask, omac_mask, or monitor_vif pointers it set before the failure, and the accompanying firmware device information remains registered. This results in a use‑after‑free condition that can be triggered if an attacker can cause the interface addition to fail, allowing dereferencing of a stale reference and potentially arbitrary code execution with kernel privileges.

Affected Systems

The vulnerability is confined to the Linux kernel’s mt76/mt7915 wireless driver module. Any installation of the Linux kernel that contains this driver prior to the fix is affected. No vendor‑specific version range is published, so all kernels that include the mt7915 driver before the patch are considered at risk.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the issue is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. However, the kernel use‑after‑free severity is high; if an attacker can stimulate a failed add_interface operation—either locally by manipulating network configuration, or remotely if monitor mode or Wi‑Fi management controls are exposed—privilege escalation to kernel level becomes possible. The attack vector is inferred based on the need to trigger interface creation failure. Existing conditions for exploitation are narrow, but the impact is severe if successfully achieved.

Generated by OpenCVE AI on September 19, 2026 at 14:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest release that includes the mt7915 driver patch
  • Reboot the system so the new kernel and driver are loaded
  • After reboot, reinstall or update the mt7915 firmware components to ensure consistency with the patched driver

Generated by OpenCVE AI on September 19, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unwind state on add_interface failure When mt76_wcid_alloc() fails, mt7915_add_interface() returned without clearing the vif_mask/omac_mask bits it had already set, without removing the firmware dev info added earlier, and without clearing a monitor_vif pointer to the vif mac80211 is about to free. mac80211 does not call remove_interface() for a failed add, so the indices and firmware dev entry leaked permanently and testmode could dereference the stale monitor_vif. Add a proper error unwind.
Title wifi: mt76: mt7915: unwind state on add_interface failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:10.084Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90368

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:35.917

Modified: 2026-09-17T17:17:35.917

Link: CVE-2026-90368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses