PT-2026-94714 · Linux · Linux Kernel

CVE-2026-90366

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the mt7996 driver where the mt7996 mcu beacon cntdwn() function emits two bss bcn cntdwn tlv entries during an active CSA countdown, but the MT7996 BEACON UPDATE SIZE only reserves space for one. When MBSSID is enabled and a near-maximum beacon template is used, the additional 8 bytes can cause the offload command to exceed the MT7996 MAX BSS OFFLOAD SIZE, leading to a system crash via skb over panic(). CSA (Channel Switch Announcement) is a mechanism used to notify clients that the access point is changing channels.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102923
CVE-2026-90366
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel