PT-2026-94705 · Linux · Linux Kernel

CVE-2026-90357

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the mt7915 driver of the mt76 wifi module where a Target Wake Time (TWT) flow is added to dev->twt list before the agreement is sent to the firmware. If the MCU rejects the agreement, the error path fails to unlink the flow, leaving it linked without the flowid mask being set. This can lead to the flow slot being reused and cleared via memset while still on the list, resulting in the corruption of twt list. Additionally, removing a station can leave a dangling entry that is subsequently processed by the mt7915 mac twt sched list add() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103011
CVE-2026-90357
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel