Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-90377
Published: September 18, 2026
Vulnerability identifier: #VU151118
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90377
CWE-ID: CWE-670
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause received data to stall and be reordered.
The vulnerability exists due to incorrect queue selection in the mt76 RX data queuing logic when releasing RRO 3.0 RX data. A remote attacker can send wireless data to cause received data to stall and be reordered.
Affected software
Linux kernel
How to mitigate CVE-2026-90377
Install security update from vendor's repository.