Incorrect Calculation of Buffer Size in Linux kernel - CVE-2026-90366
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an incorrect buffer size calculation in the MT7996 beacon update size calculation when processing a beacon update while a CSA countdown is active. A local privileged user can trigger the emission of two bss_bcn_cntdwn_tlv entries to cause a denial of service.
Exploitation requires MBSSID to be enabled and a near-maximum beacon template.
Affected software
How to mitigate CVE-2026-90366
External References
- https://git.kernel.org/stable/c/1a51aff0e048dc5b8252d65808b79939c942d6ec
- https://git.kernel.org/stable/c/1d348f96623ec20d700af7d4dfc00a74da6238ac
- https://git.kernel.org/stable/c/45d8896e4cffffb2c6554ccbec6efe7a0d53166f
- https://git.kernel.org/stable/c/50c66bab321140c49aa2ed779a3ec9d2f085b458
- https://git.kernel.org/stable/c/bc1d694a1ffe0062c3adf0db1d64ad54454398ec