« Volver al listado

CVE-2026-90376

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP

Problem: MCU command timeout while the firmware state is normal, and the firmware keeps showing the error log "ERROR!! NO PAUSE...".

Root cause: If the MLD_ID field in the TXD is neither the primary link id nor the secondary link id, it may lead to a firmware busy loop when the third link is in power saving mode.

Remap frames directed to a third link to the primary link wcid. Since TX status events and txfree completions carry the wcid the firmware saw, use the remapped wcid for packet id tracking and non-AQL packet accounting as well, while the frame keeps its original link context for addressing, band and OMAC selection.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90376",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d6f6b3a65660d183ef33f5a6582fd3b47174fe5a",
              "lessThan": "5183b9f092fc0041618f38f895bd0ad860c26ca9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "85cd5534a3f2ec93e7d88713a77df5b4255520df",
              "lessThan": "0a951ff6704db7b46c3f6d03b77e6053122be8ab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "85cd5534a3f2ec93e7d88713a77df5b4255520df",
              "lessThan": "ce35ecffc96e6d097d27b6fe30677a2cfe2e0461",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.18.33",
              "lessThan": "6.18.52",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/mediatek/mt76/mt7996/mac.c",
            "drivers/net/wireless/mediatek/mt76/mt7996/main.c",
            "drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/wireless/mediatek/mt76/mt7996/mac.c",
            "drivers/net/wireless/mediatek/mt76/mt7996/main.c",
            "drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:36.823",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0a951ff6704db7b46c3f6d03b77e6053122be8ab",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5183b9f092fc0041618f38f895bd0ad860c26ca9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ce35ecffc96e6d097d27b6fe30677a2cfe2e0461",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP\n\nProblem:\nMCU command timeout while the firmware state is normal, and the\nfirmware keeps showing the error log \"ERROR!! NO PAUSE...\".\n\nRoot cause:\nIf the MLD_ID field in the TXD is neither the primary link id nor the\nsecondary link id, it may lead to a firmware busy loop when the third\nlink is in power saving mode.\n\nRemap frames directed to a third link to the primary link wcid. Since\nTX status events and txfree completions carry the wcid the firmware\nsaw, use the remapped wcid for packet id tracking and non-AQL packet\naccounting as well, while the frame keeps its original link context\nfor addressing, band and OMAC selection."
    }
  ],
  "lastModified": "2026-09-17T17:17:36.823",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}