{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90381","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.809Z","datePublished":"2026-09-17T16:09:18.603Z","dateUpdated":"2026-09-18T17:54:58.601Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:58.601Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()\n\nWhen performing channel switches on different radios within a short\ntimeframe, channel contexts with different bands can be carried for\neach struct ieee80211_vif_chanctx_switch.\n\nRework mt76_switch_vif_chanctx() to properly handle this scenario."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - CSA IEs in a received Beacon (ieee80211_rx_mgmt_beacon → ieee80211_sta_process_chanswitch → ieee80211_link_reserve_chanctx) or Channel Switch action frame (ieee80211_sta_rx_queued_mgmt) make ieee80211_chsw_switch_vifs call mt76_switch_vif_chanctx with one ieee80211_vif_chanctx_switch per radio; those 802.11 frames are radio-range, not a routable IP protocol.\nAC:L - ieee80211_vif_use_reserved_switch returns -EAGAIN until every in-place reservation is reserved_ready, then ieee80211_chsw_switch_vifs batches them into one CHANCTX_SWMODE_SWAP_CONTEXTS call; an AP/MLD that puts CSA IEs on two mt7996 bands with matching counts makes both ready in order with no victim-only race.\nPR:N - ieee80211_rx_mgmt_beacon only needs ieee80211_rx_our_beacon() BSSID match on an associated STA, and mt7996 sets CHANCTX_STA_CSA so this path is used; beacons are unauthenticated, so the AP or a radio-range BSSID spoof needs no Linux capability or account.\nUI:N - An already-associated station runs ieee80211_csa_switch_work → ieee80211_link_use_reserved_context when the CSA count elapses and automatically enters mt76_switch_vif_chanctx; no extra click, reconnect, or mount is required at trigger time.\nS:U - Aliased mlink->ctx, the leftover phy->chanctx on non-first radios, and any resulting host-kernel heap UAF stay inside this machine’s mt76/mac80211; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The pre-fix function set every mlink->ctx to vifs[0].new_ctx. After that first ieee80211_chanctx is kfree_rcu’d (ieee80211_free_chanctx when the first vif/link unassigns while others remain), mt76_vif_link_phy() still does mlink->ctx->drv_priv and reads ctx->phy from the freed object, a kernel info-leak UAF.\nI:H - The same dangling mlink->ctx makes mt76_vif_link_phy() return ctx->phy from reallocatable freed ieee80211_chanctx memory; callers such as mt7996_link_info_changed then issue MCU updates (mt7996_mcu_add_bss_info and similar) through that forged mt76_phy pointer, a kernel write/control-flow primitive.\nA:H - mt76_vif_link_phy() on the stale mlink->ctx oopses after the aliased chanctx is freed; the pre-fix path also skipped mt76_phy_update_channel for every radio but vifs[0], leaving that PHY’s phy->chanctx pointing at the old ctx that ieee80211_vif_use_reserved_switch kfree_rcu’s, taking the radio down."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/channel.c"],"versions":[{"version":"82334623af0cd2154633cdb007719a321048fafc","lessThan":"063169a2755abdcbe7698d98360336abb6bef414","status":"affected","versionType":"git"},{"version":"82334623af0cd2154633cdb007719a321048fafc","lessThan":"70869cc429fffc77de51e7777c0ecb651e8fca07","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt76/channel.c"],"versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/063169a2755abdcbe7698d98360336abb6bef414"},{"url":"https://git.kernel.org/stable/c/70869cc429fffc77de51e7777c0ecb651e8fca07"}],"title":"wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()","x_generator":{"engine":"bippy-1.2.0"}}}}