Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: fix RX data queuing of RRO 3.0

For RRO 3.0, RX data released from a RRO data queue should be put to
the indicator queue. The frames are processed and completed in the
context of the indicator queue NAPI, which only polls skbs queued on
the MT_RXQ_RRO_IND list; frames queued under the data queue id are
left sitting on that list until the data queue NAPI happens to run,
stalling and reordering RX data.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via RX Data Stalling
Action: Assess Impact
AI Analysis

Impact

In the Linux kernel’s mt76 Wi‑Fi driver, a logic flaw in the handling of Receive‑Rx Order (RRO) 3.0 caused frames to be placed in an incorrect queue. The frames were never scheduled for immediate processing and sat on the data queue until its associated NAPI poll happened to run, leading to delayed delivery and out‑of‑order reception. This defect could degrade network performance or cause packet loss, potentially interrupting time‑critical traffic and creating a denial‑of‑service condition within the device’s wireless subsystem. The vulnerability arises from improper queue management and concurrency handling, highlighting a weakness where data is processed out of sequence.

Affected Systems

This flaw affects Linux kernel builds that include the mt76 driver with RRO 3.0 support. All Linux distributions shipping a kernel that bundles the mt76 driver, regardless of vendor, are potentially impacted, as the CPE indicates the generic Linux kernel and the vendor list includes Linux:Linux. No specific version ranges are supplied in the CNA data, but the fix is committed to the kernel source via the three Git references provided.

Risk and Exploitability

The exploit probability is very low, with an EPSS score of < 1 %. The vulnerability is not listed in CISA’s KEV catalog and no public exploit has been reported. Nonetheless, because the flaw can stall and reorder transmit data, a determined attacker who can send crafted traffic to a device using RRO 3.0 may be able to induce a loss of service or degrade performance. The risk is moderate due to the lack of a known CVSS score, but the potential impact on stability makes remediation advisable.

Generated by OpenCVE AI on September 19, 2026 at 05:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the mt76 driver fix
  • Rebuild or reconfigure the kernel to use the updated mt76 module if custom builds are in use
  • Use kernel configuration options to disable RRO 3.0 support until a verified patch is deployed

Generated by OpenCVE AI on September 19, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-482
CWE-589

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RX data queuing of RRO 3.0 For RRO 3.0, RX data released from a RRO data queue should be put to the indicator queue. The frames are processed and completed in the context of the indicator queue NAPI, which only polls skbs queued on the MT_RXQ_RRO_IND list; frames queued under the data queue id are left sitting on that list until the data queue NAPI happens to run, stalling and reordering RX data.
Title wifi: mt76: fix RX data queuing of RRO 3.0
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:16.009Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90377

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:36.927

Modified: 2026-09-17T17:17:36.927

Link: CVE-2026-90377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:30:16Z

Weaknesses
  • CWE-482

    Comparing instead of Assigning

  • CWE-589

    Call to Non-ubiquitous API