Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt792x: Fix memory leak in SDIO TX path

When tx_prepare_skb() returns an error in the SDIO TX path, the
skb is not freed, leading to a memory leak. This can occur when
zero-length frames (such as WNM NULL frames) are dropped to prevent
potential hardware TX hangs.

Fix this by properly releasing the skb with ieee80211_tx_status_ext()
when tx_prepare_skb() fails.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s mt76 driver for the mt792x wireless chip. In the SDIO transmit path, if tx_prepare_skb() returns an error, the surrounding socket buffer is not freed, resulting in a kernel memory leak. The condition is triggered when zero‑length frames such as WNM NULL frames are intentionally dropped to avoid hardware transmit hangs. Repeated failures can accumulate unfreed allocations in the kernel, potentially exhausting kernel memory and destabilizing the host, which manifests as a denial‑of‑service scenario that can affect system availability for users and services.

Affected Systems

Linux kernel builds that incorporate the mt76 mt792x driver are affected. No precise kernel release numbers are supplied, so any kernel containing the unpatched mt792x implementation may be vulnerable. Embedded or IoT platforms using MediaTek’s SDIO‑based WiFi chips are likely candidates.

Risk and Exploitability

Based on the description, it is inferred that the leak could be triggered by repeatedly dropping zero‑length frames over the WiFi interface, a remote network‑based vector. The EPSS score is below 1 %, indicating a low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. While the flaw does not require elevated privileges, its impact is significant: kernel memory exhaustion can cause a system crash or reboot. Defenders should treat this as a low‑probability, high‑impact issue that warrants prompt patching.

Generated by OpenCVE AI on September 19, 2026 at 13:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that releases the skb when tx_prepare_skb() fails, or upgrade to a kernel version that contains the fix.
  • Restart the WiFi interface or reboot the system after patching to ensure the driver is reloaded.
  • Monitor kernel memory usage and system stability for signs of a remaining leak, and consider disabling or limiting use of the SDIO WiFi interface if the patch cannot be applied promptly.

Generated by OpenCVE AI on September 19, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: Fix memory leak in SDIO TX path When tx_prepare_skb() returns an error in the SDIO TX path, the skb is not freed, leading to a memory leak. This can occur when zero-length frames (such as WNM NULL frames) are dropped to prevent potential hardware TX hangs. Fix this by properly releasing the skb with ieee80211_tx_status_ext() when tx_prepare_skb() fails.
Title wifi: mt76: mt792x: Fix memory leak in SDIO TX path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:16.655Z

Reserved: 2026-09-11T19:38:34.808Z

Link: CVE-2026-90378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.040

Modified: 2026-09-17T17:17:37.040

Link: CVE-2026-90378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:15Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime