Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP

Problem:
MCU command timeout while the firmware state is normal, and the
firmware keeps showing the error log "ERROR!! NO PAUSE...".

Root cause:
If the MLD_ID field in the TXD is neither the primary link id nor the
secondary link id, it may lead to a firmware busy loop when the third
link is in power saving mode.

Remap frames directed to a third link to the primary link wcid. Since
TX status events and txfree completions carry the wcid the firmware
saw, use the remapped wcid for packet id tracking and non-AQL packet
accounting as well, while the frame keeps its original link context
for addressing, band and OMAC selection.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via firmware busy loop
Action: Apply Patch
AI Analysis

Impact

The Linux kernel mt76 driver for MT7996 contains a logic flaw: if the MLD_ID field in a transmit descriptor is neither the primary link id nor the secondary link id, the firmware enters a busy loop and repeatedly logs "ERROR!! NO PAUSE...". This flaw results from improper input validation (CWE-20) and effectively freezes the networking stack for the affected device.

Affected Systems

This vulnerability affects any Linux kernel that includes the mt76 driver for MT7996 hardware. The vendor list indicates generic Linux kernels, and no specific kernel version numbers are listed. The patch is introduced in the commits referenced by the provided git URLs; kernels lacking this commit remain vulnerable.

Risk and Exploitability

The EPSS score is reported as below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is not provided; the flaw results in a local denial of service that requires delivery of frames with an invalid MLD_ID. Based on the description, it is inferred that an attacker would need local or privileged access to inject such frames to the Wi‑Fi adapter, as remote injection would depend on other network‑layer weaknesses not described here. The overall risk remains low, but the issue should be remediated promptly.

Generated by OpenCVE AI on September 19, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit fixing the MLD_ID handling in the mt76 driver.
  • Restart the system or reload the Wi‑Fi interface to ensure the driver loads the patched code.
  • Monitor system logs for the recurring "ERROR!! NO PAUSE..." message to confirm the issue is resolved.

Generated by OpenCVE AI on September 19, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Problem: MCU command timeout while the firmware state is normal, and the firmware keeps showing the error log "ERROR!! NO PAUSE...". Root cause: If the MLD_ID field in the TXD is neither the primary link id nor the secondary link id, it may lead to a firmware busy loop when the third link is in power saving mode. Remap frames directed to a third link to the primary link wcid. Since TX status events and txfree completions carry the wcid the firmware saw, use the remapped wcid for packet id tracking and non-AQL packet accounting as well, while the frame keeps its original link context for addressing, band and OMAC selection.
Title wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:15.361Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.823

Modified: 2026-09-17T17:17:36.823

Link: CVE-2026-90376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation