Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config

The response TLV loop advanced by tlv->len without a minimum, so a
theoretical firmware response containing a zero-length TLV could spin
forever, hanging the CPU during device probe.
The u32 payload was also read without bounds checking.
Reject a short fixed field, stop on a TLV whose length underruns the
header or overruns the skb.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (CPU)
Action: Apply Patch
AI Analysis

Impact

The flaw occurs in the Linux kernel’s mt76 driver for the MT7996 Wi‑Fi chipset. The firmware TLV parsing loop advances the offset by the length field without checking that the length is non‑zero or within bounds. A zero‑length TLV can therefore cause the loop to never progress, hanging the CPU while the device is probed. The driver also reads a 32‑bit payload without bounds checking, potentially allowing out‑of‑range reads. The net effect is a CPU‑bound denial of service that can stall system boot or network operation while the driver hangs.

Affected Systems

The vulnerability affects Linux kernel users running the mt76 driver for the MediaTek MT7996 Wi‑Fi module. Any kernel version that contains the unpatched mt76 mt7996 code prior to the recent commit is susceptible. No specific version range is listed, so all builds that include this driver are potentially at risk.

Risk and Exploitability

The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. The attack vector appears local to the device; an attacker would need to supply a firmware response containing a malformed TLV during device probe or a malicious rebuild of the firmware. If successful, the firmware parsing loop would spin forever, consuming CPU resources and leading to a denial of service. Because the immediate impact is limited to a device probe, widespread network exploitation is unlikely without physical access or firmware control.

Generated by OpenCVE AI on September 19, 2026 at 05:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the mt76 mt7996 patch found in the referenced kernel commits
  • If a kernel upgrade cannot be performed immediately, disable the mt76 driver for MT7996 to avoid device probe during boot
  • Monitor kernel logs and CPU usage for signs of stalled firmware parsing and consider disabling or replacing the affected Wi‑Fi hardware until a patch is applied

Generated by OpenCVE AI on September 19, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129
CWE-670

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config The response TLV loop advanced by tlv->len without a minimum, so a theoretical firmware response containing a zero-length TLV could spin forever, hanging the CPU during device probe. The u32 payload was also read without bounds checking. Reject a short fixed field, stop on a TLV whose length underruns the header or overruns the skb.
Title wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:11.398Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.147

Modified: 2026-09-17T17:17:36.147

Link: CVE-2026-90370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:30:16Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-670

    Always-Incorrect Control Flow Implementation