Use-after-free in Linux kernel - CVE-2026-90368
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to dereference a stale monitor_vif pointer.
The vulnerability exists due to use-after-free in mt7915_add_interface() when mt76_wcid_alloc() fails during interface addition. A local user can trigger a failed interface addition to dereference a stale monitor_vif pointer.
mac80211 does not call remove_interface() when interface addition fails.