PT-2026-94705 · Linux · Linux Kernel
CVE-2026-90357
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the mt7915 driver of the mt76 wifi module where a Target Wake Time (TWT) flow is added to
dev->twt list before the agreement is sent to the firmware. If the MCU rejects the agreement, the error path fails to unlink the flow, leaving it linked without the flowid mask being set. This can lead to the flow slot being reused and cleared via memset while still on the list, resulting in the corruption of twt list. Additionally, removing a station can leave a dangling entry that is subsequently processed by the mt7915 mac twt sched list add() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel