Answer in brief
CVE-2026-90356 records a Unknown severity vulnerability in wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ace5d3b6b49e8391beb4d7244348ba7da5298878 <2b10eb3636d0c4cb6b763e045ec1294dbd70f5ad || >=ace5d3b6b49e8391beb4d7244348ba7da5298878 <8826d7a5e2dd727aa96456ccd58b33d2b080e935 || >=ace5d3b6b49e8391beb4d7244348ba7da5298878 <7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7 | 2b10eb3636d0c4cb6b763e045ec1294dbd70f5ad, 8826d7a5e2dd727aa96456ccd58b33d2b080e935, 7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset mt7996_mac_reset_vif_iter() queues non-default vif links for kfree_rcu while dev->wcid[] still holds pointers to the wcid embedded in each freed link; mt76_reset_device() then dereferences those entries and runs mt76_wcid_cleanup() on them. If a grace period elapses in between, the cleanup operates on freed memory. Run mt76_reset_device() first, so the wcid entries are cleaned up and cleared while the links are still valid.
Quoted source text, attributed separately from HOL analysis.