« Volver al listado

CVE-2026-90373

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear

mt7915_remove_interface() cleared the wcid mask bit with no lock held and before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared with the allocators, which all run under dev->mt76.mutex; on DBDC the two wiphys share one mt76_dev, so this raced add_interface/sta_add on the other band and could leak or double-hand-out a wcid. Clearing the bit before the RCU pointer also let a concurrent allocation reuse the index and publish its wcid, which the subsequent NULL assignment then wiped. Move the clear into the existing mutex section, after the RCU pointer is cleared.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90373",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f3049b88b2b32326df97461813ae73e8bbc296fc",
              "lessThan": "5dce25f1d609ba991a9c22c27be586c92f03ed77",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f3049b88b2b32326df97461813ae73e8bbc296fc",
              "lessThan": "b4a41a47a67c788e6b0625fa517ec8872e99bb6c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f3049b88b2b32326df97461813ae73e8bbc296fc",
              "lessThan": "a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f3049b88b2b32326df97461813ae73e8bbc296fc",
              "lessThan": "6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/mediatek/mt76/mt7915/main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/mediatek/mt76/mt7915/main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:36.503",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5dce25f1d609ba991a9c22c27be586c92f03ed77",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b4a41a47a67c788e6b0625fa517ec8872e99bb6c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear\n\nmt7915_remove_interface() cleared the wcid mask bit with no lock held and\nbefore clearing the RCU wcid pointer. The mask is a non-atomic RMW shared\nwith the allocators, which all run under dev->mt76.mutex; on DBDC the two\nwiphys share one mt76_dev, so this raced add_interface/sta_add on the\nother band and could leak or double-hand-out a wcid. Clearing the bit\nbefore the RCU pointer also let a concurrent allocation reuse the index\nand publish its wcid, which the subsequent NULL assignment then wiped.\nMove the clear into the existing mutex section, after the RCU pointer is\ncleared."
    }
  ],
  "lastModified": "2026-09-17T17:17:36.503",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}