Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear

mt7915_remove_interface() cleared the wcid mask bit with no lock held and
before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared
with the allocators, which all run under dev->mt76.mutex; on DBDC the two
wiphys share one mt76_dev, so this raced add_interface/sta_add on the
other band and could leak or double-hand-out a wcid. Clearing the bit
before the RCU pointer also let a concurrent allocation reuse the index
and publish its wcid, which the subsequent NULL assignment then wiped.
Move the clear into the existing mutex section, after the RCU pointer is
cleared.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A race condition in the Linux kernel wifi driver mt7915 allows the wcid mask to be cleared without holding the necessary mutex and before the RCU pointer is cleared. The mask is a non‑atomic read‑modify‑write bit shared with allocators that run under the same mutex. When the mask is cleared prematurely, a concurrent add_interface or sta_add operation on another band can leak a wcid index or hand it out twice, and a new allocation can reuse the index and publish its wcid only to be null‑assigned immediately afterwards. This misuse of the mask can corrupt driver data structures, potentially causing a kernel panic or disrupting Wi‑Fi traffic, resulting in a denial of service to the affected system.

Affected Systems

The vulnerability is present in the Linux kernel, affecting all releases that include the mt76/mt7915 driver module before the patch. The exact kernel versions are not specified in the advisory, so any installation using this Wi‑Fi driver should consider updating.

Risk and Exploitability

The EPSS score is reported as <1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is most likely local or confined to systems that can manipulate the Wi‑Fi driver (e.g., via physical or software control of the interface). An attacker with sufficient privileges to interact with the driver would need to trigger a race between interface removal and station addition to exercise the flaw. The impact, if successfully exploited, would be a kernel crash or loss of Wi‑Fi connectivity, not remote code execution.

Generated by OpenCVE AI on September 19, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version containing the mt76/mt7915 fix so that the wcid mask is cleared only while holding the mutex and after the RCU pointer is cleared.
  • If an immediate kernel update is unavailable, temporarily unload or blacklist the mt76/mt7915 Wi‑Fi driver modules and disable the Wi‑Fi interface until the patch is applied to prevent the race from occurring.
  • Disable Dual‑Band Dual‑Connectivity (DBDC) mode or otherwise prevent concurrent add_interface/sta_add operations that can trigger the race condition while the driver remains active.

Generated by OpenCVE AI on September 19, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear mt7915_remove_interface() cleared the wcid mask bit with no lock held and before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared with the allocators, which all run under dev->mt76.mutex; on DBDC the two wiphys share one mt76_dev, so this raced add_interface/sta_add on the other band and could leak or double-hand-out a wcid. Clearing the bit before the RCU pointer also let a concurrent allocation reuse the index and publish its wcid, which the subsequent NULL assignment then wiped. Move the clear into the existing mutex section, after the RCU pointer is cleared.
Title wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:13.368Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90373

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.503

Modified: 2026-09-17T17:17:36.503

Link: CVE-2026-90373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')