Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-90377

 

Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-90377

Published: September 18, 2026


Vulnerability identifier: #VU151118
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90377
CWE-ID: CWE-670
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause received data to stall and be reordered.

The vulnerability exists due to incorrect queue selection in the mt76 RX data queuing logic when releasing RRO 3.0 RX data. A remote attacker can send wireless data to cause received data to stall and be reordered.


Affected software

Linux kernel

How to mitigate CVE-2026-90377

Install security update from vendor's repository.


External References

Related Security Bulletins