Answer in brief
CVE-2026-90368 records a Unknown severity vulnerability in wifi: mt76: mt7915: unwind state on add_interface failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b619e01380eedf24e8d26a367e94e0ccaeb0c3dd <218fdf0fcb796b8d281dbdd4a6144c5a8fc7fd0f || >=b619e01380eedf24e8d26a367e94e0ccaeb0c3dd <507eddb8175a67df5086354b92d6a4fd7f6f1f96 || >=b619e01380eedf24e8d26a367e94e0ccaeb0c3dd <71bf9de2ab3fb2c54bedb0b4c9b468d2e1d55280 || >=b619e01380eedf24e8d26a367e94e0ccaeb0c3dd <2fb6480c52f611338e1b0abe5e6219be1fc9ab75 | 218fdf0fcb796b8d281dbdd4a6144c5a8fc7fd0f, 507eddb8175a67df5086354b92d6a4fd7f6f1f96, 71bf9de2ab3fb2c54bedb0b4c9b468d2e1d55280, 2fb6480c52f611338e1b0abe5e6219be1fc9ab75 |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unwind state on add_interface failure When mt76_wcid_alloc() fails, mt7915_add_interface() returned without clearing the vif_mask/omac_mask bits it had already set, without removing the firmware dev info added earlier, and without clearing a monitor_vif pointer to the vif mac80211 is about to free. mac80211 does not call remove_interface() for a failed add, so the indices and firmware dev entry leaked permanently and testmode could dereference the stale monitor_vif. Add a proper error unwind.
Quoted source text, attributed separately from HOL analysis.