PT-2026-94701 · Linux · Linux Kernel

CVE-2026-90353

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the mt7915 wireless driver. When mt7915 register ext phy() succeeds but a subsequent failure occurs in mt7915 init debugfs() or mt7915 coredump register(), the system unwinds through free phy2. This process calls ieee80211 free hw() on the external PHY hardware while it remains registered with mac80211, because mt76 unregister device() only unregisters the main hardware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101981
CVE-2026-90353
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel