-
CVE-2026-90350
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:08:58
- Zuletzt bearbeitet 17.09.2026 17:17:33
- Erkennungen
wifi: mt76: reject out-of-range link ids in mt76_vif_link()
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: reject out-of-range link ids in mt76_vif_link() mt76_vif_link() indexes mvif->link[] without validating link_id, but callers pass mvif->deflink_id / msta->deflink_id, which hold IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added. Since IEEE80211_MLD_MAX_NUM_LINKS is 15, that reads one element past the end of the array, aliasing mt76_vif_data.offchannel_link. Reachable via mt7996_set_tsf()/mt7996_offset_tsf() and mt7996_net_fill_forward_path(). Bounds check link_id and return NULL, matching mt7996_sta_link() and mt7996_sta_link_protected().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
a9384b36a42afc2d715eb74c19a7ee558f09ef82
Version <
13f6a9c786022d5213e84d494cc8717c378f5395
Status
affected
Version
a9384b36a42afc2d715eb74c19a7ee558f09ef82
Version <
c1442c345ca8da857fadea1d0797b97347ab6984
Status
affected
Version
a9384b36a42afc2d715eb74c19a7ee558f09ef82
Version <
9ba744a28c26eaa5cae930688a22e01888395308
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/13f6a9c786022d5213e84d494cc8717c378f5395
https://git.kernel.org/stable/c/c1442c345ca8da857fadea1d0797b97347ab6984
https://git.kernel.org/stable/c/9ba744a28c26eaa5cae930688a22e01888395308