{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90371","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.808Z","datePublished":"2026-09-17T16:09:12.046Z","dateUpdated":"2026-09-18T17:54:53.216Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:53.216Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: fix RXDMAD_C buffer recycling race\n\nThe RXDMAD_C buffers come from the RRO data queues' page pools, which are\nbound to a different NAPI, so the direct page-pool recycle used here could\nrace the owning NAPI; take the non-direct path as is already done for WED\nRX queues."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - Received 802.11 frames are completed by HW-RRO v3.1 into the RXDMAD_C ring; mt7996_irq_handler/mt7996_irq_tasklet schedules napi[MT_RXQ_RRO_RXDMAD_C] and mt76_dma_rx_poll→mt76_dma_rx_process→mt76_dma_get_rxdmad_c_buf recycles those payload pages. A radio-range peer supplies the frames; WiFi is adjacent, not a routable IP transport.\nAC:L - The attacker drives both NAPIs by flooding 802.11 traffic: the RRO data-queue NAPI runs mt76_dma_rx_fill→page_pool_alloc_frag on the owning pool, while RXDMAD_C drops completions (SDL0 vs SKB_WITH_OVERHEAD of MT7996_RX_BUF_SIZE, or extra frags in mt76_add_fragment) and calls mt76_put_page_pool_buf(..., true) into the same unlocked alloc.cache.\nPR:N - mt76_dma_get_rxdmad_c_buf runs on the WiFi RX DMA completion path with no host credential check; a nearby unauthenticated station can send frames that HW-RRO v3.1 writes into RXDMAD_C (rx_token_id/SDL0) without any kernel account.\nUI:N - With the mt7996/mt7992 interface already up in HWRRO v3.1, the attacker triggers mt76_dma_rx_process on MT_RXQ_RRO_RXDMAD_C solely by transmitting frames; no mount, click, or other victim action is required.\nS:U - The race corrupts the host kernel page_pool alloc.cache for the RRO data queues (dev->q_rx[t->qid]->page_pool) in the same kernel; it does not cross a VM, IOMMU, or guest/host boundary.\nC:H - Concurrent lockless updates of pool->alloc.cache/count in page_pool_recycle_in_cache versus page_pool_alloc_frag can issue the same RX page twice or return a stale pointer, a use-after-free of packet buffers that enables disclosure of kernel or packet memory.\nI:H - The same unlocked recycle can bump alloc.count past PP_ALLOC_CACHE_SIZE so a later page_pool_recycle_in_cache writes a netmem pointer out of bounds, and a double-issued page lets attacker-controlled 802.11 DMA clobber reused kernel memory.\nA:H - A corrupted page_pool alloc.cache yields invalid page pointers and use-after-free in mt76_dma_rx_fill/mt76_dma_rx_process, which oopses or panics the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/dma.c"],"versions":[{"version":"e50d4d710efd2dbc46965e9608bbb502bcfc5c99","lessThan":"7ac05ed3a50e511c93f8506e555709a208dfce0a","status":"affected","versionType":"git"},{"version":"e50d4d710efd2dbc46965e9608bbb502bcfc5c99","lessThan":"a273dc3b86a7d983d643827d3d3c795d55d8f632","status":"affected","versionType":"git"},{"version":"e50d4d710efd2dbc46965e9608bbb502bcfc5c99","lessThan":"e1f97c10a4ec2b9db69a134b757304399ca903ce","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/dma.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7ac05ed3a50e511c93f8506e555709a208dfce0a"},{"url":"https://git.kernel.org/stable/c/a273dc3b86a7d983d643827d3d3c795d55d8f632"},{"url":"https://git.kernel.org/stable/c/e1f97c10a4ec2b9db69a134b757304399ca903ce"}],"title":"wifi: mt76: fix RXDMAD_C buffer recycling race","x_generator":{"engine":"bippy-1.2.0"}}}}