PT-2026-94698 · Linux · Linux Kernel

CVE-2026-90350

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the mt76 wifi driver where the mt76 vif link() function indexes the mvif->link[] array without validating the link id. When callers pass mvif->deflink id or msta->deflink id containing the value IEEE80211 LINK UNSPECIFIED (0xf) before the first link is added, the system reads one element past the end of the array because IEEE80211 MLD MAX NUM LINKS is 15. This results in aliasing mt76 vif data.offchannel link. The flaw is reachable via the mt7996 set tsf(), mt7996 offset tsf(), and mt7996 net fill forward path() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90350
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel