Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()

When performing channel switches on different radios within a short
timeframe, channel contexts with different bands can be carried for
each struct ieee80211_vif_chanctx_switch.

Rework mt76_switch_vif_chanctx() to properly handle this scenario.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s mt76 Wi‑Fi driver, the routine mt76_switch_vif_chanctx() failed to handle channel context switching when different radios shifted between bands in quick succession. The bug allowed mismatched channel contexts to be applied, which could trigger undefined behavior and cause the driver—and consequently the kernel—to crash. Because a kernel panic terminates all network activity, the primary impact is a denial‑of‑service to wireless clients on the affected device.

Affected Systems

The issue targets the Linux kernel’s mt76 wireless driver component, which is included in many mainstream Linux distributions. Any system running a kernel that has not been updated to a revision incorporating the patch commit referenced in the advisory is potentially exposed. No specific release numbers are listed, so all kernels with an unpatched mt76 driver are in scope.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity DoS risk. The EPSS metric is below 1%, reflecting a very low likelihood of observed exploitation in the wild, and the vulnerability is not currently cataloged in the CISA KEV list. Exploitation requires a local user with the ability to trigger rapid, cross‑band channel switches—such as a malicious application or a user with network‑driver control—making the attack vector local and privileged. No remote‑network exploitation is documented or implied by the CVE text.

Generated by OpenCVE AI on September 19, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that includes the mt76_switch_vif_chanctx() fix – see the advisory commits
  • Restart the networking stack or reboot the system to ensure the driver loads with the corrected context handling
  • If rapid cross‑band channel switching is necessary, configure the radios to use distinct bands or schedule switches to avoid tight timing that could re‑trigger the bug

Generated by OpenCVE AI on September 19, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() When performing channel switches on different radios within a short timeframe, channel contexts with different bands can be carried for each struct ieee80211_vif_chanctx_switch. Rework mt76_switch_vif_chanctx() to properly handle this scenario.
Title wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:58.601Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90381

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.397

Modified: 2026-09-18T18:17:56.307

Link: CVE-2026-90381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast