SB20260918326 - Improper Check for Unusual or Exceptional Conditions in Linux kernel mt76 mt7996 driver



SB20260918326 - Improper Check for Unusual or Exceptional Conditions in Linux kernel mt76 mt7996 driver

Published: September 18, 2026

Security Bulletin ID SB20260918326
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-90351)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an exceptional condition in the mt7996 WED initialization path when initializing the secondary hif2 WED function after primary WED attachment fails. A local user can trigger the affected probe path to cause a system crash.

The secondary hif2 setup can re-enable hwrro_mode after the failed primary attachment disabled it.


Remediation

Install update from vendor's website.