Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-90351

 

Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-90351

Published: September 18, 2026


Vulnerability identifier: #VU151139
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90351
CWE-ID: CWE-754
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an exceptional condition in the mt7996 WED initialization path when initializing the secondary hif2 WED function after primary WED attachment fails. A local user can trigger the affected probe path to cause a system crash.

The secondary hif2 setup can re-enable hwrro_mode after the failed primary attachment disabled it.


Affected software

Linux kernel

How to mitigate CVE-2026-90351

Install security update from vendor's repository.


External References

Related Security Bulletins