PT-2026-94704 · Linux · Linux Kernel

CVE-2026-90356

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the mt7996 wireless driver. The function mt7996 mac reset vif iter() queues non-default virtual interface (vif) links for kfree rcu while the dev->wcid[] array still maintains pointers to the wcid embedded in those links. Subsequently, mt76 reset device() dereferences these entries to execute mt76 wcid cleanup(). If a grace period elapses before the cleanup occurs, the system operates on freed memory.
Recommendations Run mt76 reset device() before mt7996 mac reset vif iter() to ensure wcid entries are cleaned and cleared while the links remain valid.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90356
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel