Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90379
Published: September 18, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper validation of a DMA queue index in the mt76 DMA queue handling code when processing DMA queue state after a PCIe AER error causes the bus to hang. An attacker with physical access can induce a hung PCIe bus state to cause a denial of service.