{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90380","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.809Z","datePublished":"2026-09-17T16:09:17.948Z","dateUpdated":"2026-09-18T17:54:57.266Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:57.266Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete\n\nA use-after-free issue occurs in mt76_rx_poll_complete due to a race\ncondition. The STA has already been removed, but the rx_status still\nhad a pointer to the wcid in the STA.\n\nSet the links' wcid pointers to be NULL for a MLD in\nmt7925_sta_pre_rcu_remove()\n\nBUG: KASAN: invalid-access in mt76_rx_poll_complete+0x280/0x470\nCall trace:\ndump_backtrace+0xec/0x128\nshow_stack+0x18/0x28\ndump_stack_lvl+0x40/0xc8\nprint_report+0x1b8/0x710\nkasan_report+0xe0/0x144\ndo_bad_area+0x120/0x260\ndo_tag_check_fault+0x20/0x34\ndo_mem_abort+0x54/0xa8\nel1_abort+0x3c/0x5c\nel1h_64_sync_handler+0x40/0xcc\nel1h_64_sync+0x7c/0x80\nmt76_rx_poll_complete+0x280/0x470\nmt76_dma_rx_poll+0x114/0x51c\nmt792x_poll_rx+0x60/0xf8\nnapi_threaded_poll_loop+0xe0/0x450\nnapi_threaded_poll+0x80/0x9c\nkthread+0x11c/0x158\nret_from_fork+0x10/0x20"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - An 802.11be MLO peer's frames are DMA'd into mt792x_poll_rx→mt76_dma_rx_poll→mt7925_queue_rx_skb→mt7925_mac_fill_rx, which stores status->wcid from MT_RXD1_NORMAL_WLAN_IDX via mt792x_rx_get_wcid(); those bytes arrive over WiFi radio, which is adjacent rather than a routable IP transport.\nAC:L - The attacker drives both sides: data frames on a non-default MLO link keep mt76_rx_poll_complete using a secondary mt792x_link_sta.wcid that mt76_sta_pre_rcu_remove never NULLs, while a deauth/disassoc runs __sta_info_destroy. mt7925_mac_link_sta_remove then sleeps in MCU commands before clearing that idx, so the race is attacker-retryable.\nPR:N - mt76_rx_poll_complete and ieee80211_rx_mgmt_deauth→ieee80211_set_disassoc run on the WiFi RX path with no Linux credential or capability check; a radio-range MLO AP sending deauth plus data is enough, with no local account on the mt7925 client.\nUI:N - Once the mt7925 station VIF is already in an MLO association (WIPHY_FLAG_SUPPORTS_MLO is set only for NL80211_IFTYPE_STATION), the attacker triggers STA teardown and the concurrent RX by transmitting; no mount, click, or other victim action is required at exploit time.\nS:U - The UAF is of the mt792x_link_sta.wcid published in dev->wcid[] and later used in mt76_check_sta/mt76_rx_complete inside this host kernel; it does not cross a VM, IOMMU, or guest/host boundary.\nC:H - After the MLD STA is freed, mt76_check_sta and mt76_rx_convert still dereference status->wcid (wcid->sta, wcid->link_valid/link_id, wcid_to_sta()) from skb->cb, a use-after-free of the attacker-reallocatable mt792x_link_sta that enables arbitrary kernel reads.\nI:H - The same dangling wcid is written in mt76_check_sta (ewma_signal_add, wcid->inactive_count, PS flag bits) and in mt76_check_ccmp_pn (memcpy into wcid->rx_key_pn[] from the frame IV), giving a kernel write primitive through the freed mt792x_link_sta.\nA:H - KASAN already reports invalid-access in mt76_rx_poll_complete when the RX NAPI uses the freed wcid after STA removal; that use-after-free oopses or panics the kernel even without a full exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/main.c"],"versions":[{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"aaf414bf81ab4b680580871784b0b929818188eb","status":"affected","versionType":"git"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"b250943f3f8351385a17972bda001664a5c51008","status":"affected","versionType":"git"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"217f9e7bb02558759be9d9ecfe532e9708741c50","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/main.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/aaf414bf81ab4b680580871784b0b929818188eb"},{"url":"https://git.kernel.org/stable/c/b250943f3f8351385a17972bda001664a5c51008"},{"url":"https://git.kernel.org/stable/c/217f9e7bb02558759be9d9ecfe532e9708741c50"}],"title":"wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete","x_generator":{"engine":"bippy-1.2.0"}}}}