Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length

The MPDU length in the rx descriptor comes from the hardware. In
monitor mode with the fcsfail filter enabled, the hardware passes up
corrupted frames, and a corrupted frame can report a length larger
than the received buffer. The bounds check correctly discards such
frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage
frame taints the kernel, and panics it on the first such frame when
panic_on_warn is set.

Drop the WARN and discard the frame silently, matching what
commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx
status and rx path") did for the neighboring rx and tx status paths.

Observed immediately on rx with an MT7612U in fcsfail monitor mode
on a busy channel.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Immediate Update
AI Analysis

Impact

In the Linux kernel's mt76 wireless driver for devices such as the MT7612U, a corrupted frame received in monitor mode with the fcsfail filter can report an MPDU length greater than the buffer size. The driver correctly discards the frame, but the early code wrapped the discard in a WARN_ON_ONCE. When the global kernel setting panic_on_warn is enabled, this single warning taints the kernel and triggers a panic on the first occurrence, bringing the system to a halt. The flaw therefore allows a remote attacker who can transmit malformed wireless packets to force a kernel panic and disrupt service, but does not enable privilege escalation or data exfiltration.

Affected Systems

Affected systems are Linux kernel versions that include the mt76 driver path used by the MT7612U and similar devices running in monitor mode with fcsfail enabled. The patches that remove the WARN invoke the same logic as an earlier commit that silenced the warning in adjacent paths. No specific vendor names beyond “Linux” appear in the CNA fields, and the precise kernel versions before the change are not enumerated in the data.

Risk and Exploitability

The CVSS vector is unreported, but the EPSS score is below 1% and the vulnerability is not in the CISA KEV catalog, suggesting low exploitation probability at present. However, the impact of a kernel panic is severe, giving the attacker full denial‑of‑service over a network. The likely attack path is through the wireless interface, sending crafted frames while monitor mode and fcsfail are active; privileged kernel settings (panic_on_warn) are not required. Given the low EPSS, the risk remains moderate, but potential for widespread disruption warrants prompt action.

Generated by OpenCVE AI on September 19, 2026 at 05:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel that contains the patch removing the WARN_ON_ONCE for mt76x02.
  • Disable monitor mode or the fcsfail filter so corrupted frames are not routed to the driver.
  • Set /proc/sys/kernel/panic_on_warn to 0 to avoid kernel panic when a warning occurs.

Generated by OpenCVE AI on September 19, 2026 at 05:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length The MPDU length in the rx descriptor comes from the hardware. In monitor mode with the fcsfail filter enabled, the hardware passes up corrupted frames, and a corrupted frame can report a length larger than the received buffer. The bounds check correctly discards such frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage frame taints the kernel, and panics it on the first such frame when panic_on_warn is set. Drop the WARN and discard the frame silently, matching what commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx status and rx path") did for the neighboring rx and tx status paths. Observed immediately on rx with an MT7612U in fcsfail monitor mode on a busy channel.
Title wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:19.247Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90382

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.503

Modified: 2026-09-17T17:17:37.503

Link: CVE-2026-90382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:15:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption