-

CVE-2026-90356

wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset

mt7996_mac_reset_vif_iter() queues non-default vif links for kfree_rcu
while dev->wcid[] still holds pointers to the wcid embedded in each
freed link; mt76_reset_device() then dereferences those entries and
runs mt76_wcid_cleanup() on them. If a grace period elapses in between,
the cleanup operates on freed memory.

Run mt76_reset_device() first, so the wcid entries are cleaned up and
cleared while the links are still valid.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ace5d3b6b49e8391beb4d7244348ba7da5298878
Version < 2b10eb3636d0c4cb6b763e045ec1294dbd70f5ad
Status affected
Version ace5d3b6b49e8391beb4d7244348ba7da5298878
Version < 8826d7a5e2dd727aa96456ccd58b33d2b080e935
Status affected
Version ace5d3b6b49e8391beb4d7244348ba7da5298878
Version < 7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2b10eb3636d0c4cb6b763e045ec1294dbd70f5ad
https://git.kernel.org/stable/c/8826d7a5e2dd727aa96456ccd58b33d2b080e935
https://git.kernel.org/stable/c/7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7