Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss

If a peer's VHT/HE MCS map has no supported spatial stream (all fields
0x3), the loop exits with nss == 0 and the function returned (u8)-1 (255),
which was then written into the firmware sta_rec_bf beamforming fields.
Clamp the result to 0.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data integrity / Service disruption
Action: Apply patch
AI Analysis

Impact

A kernel driver for Wi‑Fi hardware incorrectly handled a case where a peer's VHT/HE MCS map contained no supported spatial streams, causing a loop to exit with nss equal to zero and the function to return the unsigned value 255. This value was then written into the firmware's beamforming configuration, potentially corrupting the device's operational parameters. The patch restricts the result to zero, preventing bad data from propagating. The flaw represents an integer underflow that could lead to corrupted firmware settings, which might result in degraded Wi‑Fi performance or a denial of service on the affected device.

Affected Systems

The vulnerability impacts the Linux kernel's mt76 driver for the mt7915 Wi‑Fi chipset, which is used in Linux distributions that include this driver. All kernel versions prior to the applied patch that ship the mt76 module are potentially affected. Specific vendor or distribution names are not listed, but the issue applies to any Linux system running the offending driver version.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity. The EPSS probability is listed as less than 1 %, implying a low likelihood of exploitation at present, and the vulnerability is not included in CISA’s KEV catalog. Exploitation would require interaction with the Wi‑Fi hardware and likely a malicious or compromised firmware payload, so the attack vector is inferred as a local or firmware‑based vector rather than a straightforward remote one. Nonetheless, because the flaw corrupts firmware settings, it could precipitate service disruption if triggered. The existing mitigation is to apply the kernel patch that clamps the value to zero.

Generated by OpenCVE AI on September 19, 2026 at 15:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the mt76 driver patch that clamps the nss value.
  • Deploy the matching firmware image for the mt7915 chipset that aligns with the patched driver.
  • Restart the Wi‑Fi interface or reboot the system to ensure the updated driver and firmware are loaded and any stale beamforming settings are cleared.

Generated by OpenCVE AI on September 19, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-189

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss If a peer's VHT/HE MCS map has no supported spatial stream (all fields 0x3), the loop exits with nss == 0 and the function returned (u8)-1 (255), which was then written into the firmware sta_rec_bf beamforming fields. Clamp the result to 0.
Title wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:54.603Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.363

Modified: 2026-09-18T18:17:55.750

Link: CVE-2026-90372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses