SB20260918305 - Always-Incorrect Control Flow Implementation in Linux kernel mediatek mt76 driver



SB20260918305 - Always-Incorrect Control Flow Implementation in Linux kernel mediatek mt76 driver

Published: September 18, 2026

Security Bulletin ID SB20260918305
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-90377)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause received data to stall and be reordered.

The vulnerability exists due to incorrect queue selection in the mt76 RX data queuing logic when releasing RRO 3.0 RX data. A remote attacker can send wireless data to cause received data to stall and be reordered.


Remediation

Install update from vendor's website.