Out-of-bounds read in Linux kernel - CVE-2026-90374
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause an out-of-bounds memory access.
The vulnerability exists due to improper validation of an array index in the mt7996_mac_fill_rx RX handler when processing a received descriptor with a corrupt or reserved band index. A remote attacker can supply a received descriptor with a corrupt or reserved band index to cause an out-of-bounds memory access.