PT-2026-94701 · Linux · Linux Kernel
CVE-2026-90353
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the mt7915 wireless driver. When
mt7915 register ext phy() succeeds but a subsequent failure occurs in mt7915 init debugfs() or mt7915 coredump register(), the system unwinds through free phy2. This process calls ieee80211 free hw() on the external PHY hardware while it remains registered with mac80211, because mt76 unregister device() only unregisters the main hardware.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel