Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: fix RXDMAD_C buffer recycling race

The RXDMAD_C buffers come from the RRO data queues' page pools, which are
bound to a different NAPI, so the direct page-pool recycle used here could
race the owning NAPI; take the non-direct path as is already done for WED
RX queues.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via race condition in Wi‑Fi driver
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s mt76 Wi‑Fi driver contains a race condition in the RXDMAD_C buffer recycling logic. The buffers come from RRO data queues and are tied to a different NAPI context; when recycled directly they can race with the owning NAPI thread, potentially corrupting memory or causing a crash. This concurrency flaw can lead to a denial of service by destabilizing the kernel packet‑handling subsystem.

Affected Systems

Any Linux kernel installation that compiles the mt76 driver without the new non‑direct recycling logic is susceptible. The advisory does not specify exact kernel versions, so all unpatched kernels that still use the original buffer recycling path are at risk. Vendors shipping kernels with mt76 should review release notes to confirm whether the fix has been applied.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity race condition. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability has not been listed in CISA KEV. Based on the description, it is inferred that an attacker might trigger the race by flooding the device with Wi‑Fi frames that queue through the RRO queues; this could be done over a wireless channel or locally. Successful exploitation could crash the kernel, leading to a denial of service.

Generated by OpenCVE AI on September 20, 2026 at 02:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a kernel version that includes the mt76 RXDMAD_C buffer recycling fix; the required code is present in the mainline kernel after the referenced commits.
  • If a kernel upgrade is not immediately possible, disable the mt76 Wi‑Fi driver or reduce wireless traffic to lower the likelihood of triggering the race condition.
  • Monitor kernel logs and NAPI queue metrics for signs of abnormal packet handling or crashes that could indicate the race is active; investigate any such incidents promptly.

Generated by OpenCVE AI on September 20, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 19 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RXDMAD_C buffer recycling race The RXDMAD_C buffers come from the RRO data queues' page pools, which are bound to a different NAPI, so the direct page-pool recycle used here could race the owning NAPI; take the non-direct path as is already done for WED RX queues.
Title wifi: mt76: fix RXDMAD_C buffer recycling race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:53.216Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.263

Modified: 2026-09-18T18:17:55.623

Link: CVE-2026-90371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')