๐Ÿ” CVE Alert

CVE-2026-90374

UNKNOWN 0.0

wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] band_idx comes from a 2-bit descriptor field (0-3) and was used directly to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference the result. A corrupt or reserved descriptor value could index out of bounds or hit a NULL phy on parts with fewer bands. Reject invalid band indices, mirroring mt7996_rx_get_wcid().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
98686cd21624c75a043e96812beadddf4f6f48e5 < 535091c587268cc783608642838a655d828eefdd 98686cd21624c75a043e96812beadddf4f6f48e5 < 0f53ece876e1f3bbb3e18f48afc4af1ee967b16c 98686cd21624c75a043e96812beadddf4f6f48e5 < b1c5cf8903bec5476a2233b4e45287b9a2213e02 98686cd21624c75a043e96812beadddf4f6f48e5 < 2243778a5fae8329ab5f18e7adcd7e03b911a1b7
Linux / Linux
6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/535091c587268cc783608642838a655d828eefdd git.kernel.org: https://git.kernel.org/stable/c/0f53ece876e1f3bbb3e18f48afc4af1ee967b16c git.kernel.org: https://git.kernel.org/stable/c/b1c5cf8903bec5476a2233b4e45287b9a2213e02 git.kernel.org: https://git.kernel.org/stable/c/2243778a5fae8329ab5f18e7adcd7e03b911a1b7