Out-of-bounds read in Linux kernel - CVE-2026-90350
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in mt76_vif_link() when processing an out-of-range link ID. A local user can cause processing of an out-of-range link ID to perform an out-of-bounds read.
The issue occurs before the first link has been added, when the default link ID is IEEE80211_LINK_UNSPECIFIED (0xf).