Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]

band_idx comes from a 2-bit descriptor field (0-3) and was used directly
to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference the
result. A corrupt or reserved descriptor value could index out of bounds
or hit a NULL phy on parts with fewer bands. Reject invalid band indices,
mirroring mt7996_rx_get_wcid().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Out‑of‑Bounds Array Index
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s mt76 Wi‑Fi driver for MT7996 hardware incorrectly uses a 2‑bit descriptor field to index the phys[] array without validating the value. The index can be 0‑3, but phys[] has a size of 3, so an index value of 3 or a reserved value can address memory beyond the array or a NULL pointer. This out‑of‑bounds access can trigger a kernel fault, causing a panic and a complete loss of system availability. Because the fault occurs during packet reception, no code execution or privilege escalation is required; the primary impact is a denial of service.

Affected Systems

Systems running a Linux kernel that incorporates the mt76 driver for MT7996 wireless adapters—including many consumer and industrial devices—are affected. The vulnerability applies to all kernel releases that include the unpatched mt76 source before the fix commit, and therefore applies to any active installation of such kernels until updated.

Risk and Exploitability

The EPSS score listed as <1 % and the absence from the CISA KEV catalog indicate a low probability of exploitation in the wild. An attacker would need to transmit malicious Wi‑Fi traffic that contains an out‑of‑bounds band index value. While no public exploits or proof‑of‑concepts have been reported, the vulnerability can be triggered by any active receiver on the air, making it feasible for a local or remote adversary to induce a kernel crash if the system is within range of a traffic source.

Generated by OpenCVE AI on September 19, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the mt76 driver change that validates the RX band index before accessing phys[].
  • Reboot the system to load the new kernel and ensure the patched driver code is in use.
  • If an immediate kernel upgrade is not possible, mitigate risk by disabling the offending Wi‑Fi interface or restricting external wireless traffic until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] band_idx comes from a 2-bit descriptor field (0-3) and was used directly to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference the result. A corrupt or reserved descriptor value could index out of bounds or hit a NULL phy on parts with fewer bands. Reject invalid band indices, mirroring mt7996_rx_get_wcid().
Title wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:14.067Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90374

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.613

Modified: 2026-09-17T17:17:36.613

Link: CVE-2026-90374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses