Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete

A use-after-free issue occurs in mt76_rx_poll_complete due to a race
condition. The STA has already been removed, but the rx_status still
had a pointer to the wcid in the STA.

Set the links' wcid pointers to be NULL for a MLD in
mt7925_sta_pre_rcu_remove()

BUG: KASAN: invalid-access in mt76_rx_poll_complete+0x280/0x470
Call trace:
dump_backtrace+0xec/0x128
show_stack+0x18/0x28
dump_stack_lvl+0x40/0xc8
print_report+0x1b8/0x710
kasan_report+0xe0/0x144
do_bad_area+0x120/0x260
do_tag_check_fault+0x20/0x34
do_mem_abort+0x54/0xa8
el1_abort+0x3c/0x5c
el1h_64_sync_handler+0x40/0xcc
el1h_64_sync+0x7c/0x80
mt76_rx_poll_complete+0x280/0x470
mt76_dma_rx_poll+0x114/0x51c
mt792x_poll_rx+0x60/0xf8
napi_threaded_poll_loop+0xe0/0x450
napi_threaded_poll+0x80/0x9c
kthread+0x11c/0x158
ret_from_fork+0x10/0x20
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to possible kernel crash or privilege escalation
Action: Apply Patch
AI Analysis

Impact

Based on the description, a race condition in the Linux kernel Wi‑Fi driver mt76 triggers a use‑after‑free in the mt792x series during station removal. When the receiver poll function dispatches, the driver accesses a stale pointer to the station’s wcid, which can corrupt memory or cause a kernel panic. An attacker who can send crafted frames to the affected device may provoke the flaw, potentially leading to a crash or, if memory corruption is hijacked, kernel‑level code execution.

Affected Systems

The vulnerability applies to all Linux kernel builds that include the mt76/mt792x Wi‑Fi driver. No specific kernel version is supplied; any in‑use kernel that supports these drivers is potentially susceptible. Updating to a kernel snapshot that contains the committed patch fixes the issue.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score is reported as under 1 %, indicating a very low current exploitation probability. It is not yet listed in the CISA KEV catalog. It is inferred that the likely attack vector is remote via malicious Wi‑Fi packets; a local attacker with physical radio access could also exploit the flaw. Without a publicly available exploit, the risk is moderate, but the potential for privilege escalation warrants timely mitigations.

Generated by OpenCVE AI on September 20, 2026 at 00:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest available Linux kernel release that incorporates the mt76/mt792x use‑after‑free fix
  • Restart the system to boot into the updated kernel
  • Ensure system inventory and deployment scripts use the updated kernel version for all hosts

Generated by OpenCVE AI on September 20, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete A use-after-free issue occurs in mt76_rx_poll_complete due to a race condition. The STA has already been removed, but the rx_status still had a pointer to the wcid in the STA. Set the links' wcid pointers to be NULL for a MLD in mt7925_sta_pre_rcu_remove() BUG: KASAN: invalid-access in mt76_rx_poll_complete+0x280/0x470 Call trace: dump_backtrace+0xec/0x128 show_stack+0x18/0x28 dump_stack_lvl+0x40/0xc8 print_report+0x1b8/0x710 kasan_report+0xe0/0x144 do_bad_area+0x120/0x260 do_tag_check_fault+0x20/0x34 do_mem_abort+0x54/0xa8 el1_abort+0x3c/0x5c el1h_64_sync_handler+0x40/0xcc el1h_64_sync+0x7c/0x80 mt76_rx_poll_complete+0x280/0x470 mt76_dma_rx_poll+0x114/0x51c mt792x_poll_rx+0x60/0xf8 napi_threaded_poll_loop+0xe0/0x450 napi_threaded_poll+0x80/0x9c kthread+0x11c/0x158 ret_from_fork+0x10/0x20
Title wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:57.266Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90380

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.297

Modified: 2026-09-18T18:17:56.080

Link: CVE-2026-90380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses