SB20260918291 - Reachable assertion in Linux kernel mediatek mt76 driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reachable assertion (CVE-ID: CVE-2026-90382)
CWE-ID: CWE-617 - Reachable Assertion
CVSSv4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a kernel panic and denial of service.
The vulnerability exists due to a reachable assertion in the mt76x02 receive-processing path when processing a corrupted wireless frame with a receive descriptor length larger than the received buffer. A remote attacker can transmit a corrupted over-the-air frame to cause a kernel panic and denial of service.
Exploitation requires monitor mode with the fcsfail filter enabled and panic_on_warn set.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17d6b89e09eac2d90272fceeba3644e92212e02f
- https://git.kernel.org/stable/c/2d31e332c13b1db7745a7bd9cf74bc105524bcac
- https://git.kernel.org/stable/c/61b1f6d92249bc34580ff19de7c69c805f82adca
- https://git.kernel.org/stable/c/6def491fe9c4e83aa8cba62d74e9d4ab751ee967
- https://git.kernel.org/stable/c/81497634d9f872fd3e8b03aada55574afff6f174
- https://git.kernel.org/stable/c/b6e7958602bd1acdb8ae92703b6689a28bcc9bc0
- https://git.kernel.org/stable/c/c65bbfc730df9ebf0fea8e286b0ad2dfab03dbfe
- https://git.kernel.org/stable/c/d55e7aede542c4c76ead82d37d0c112f21eb2ac2