CVE-2026-90367
8.8Linux · Kernel
A race condition in the Linux kernel mt7996 wifi driver allows for potential memory corruption due to improper mutex locking during SER operations.
Executive summary
A race condition in the Linux kernel mt7996 driver could allow an adjacent attacker to trigger memory corruption, potentially leading to unauthorized system access or crashes.
Vulnerability
This is a race condition vulnerability within the mt7996 wireless driver. An attacker positioned on the local network can exploit improper mutex handling during Service Event Recovery (SER) tasks to trigger memory corruption of descriptors or tokens.
Business impact
Successful exploitation of this vulnerability can result in system instability, kernel panics, or the potential for arbitrary code execution. Given the CVSS score of 8.8, this flaw represents a significant risk to confidentiality, integrity, and availability for affected wireless infrastructure. Organizations relying on Linux-based wireless hardware may face service interruptions or compromise of sensitive data transmitted over the affected network.
Remediation
Immediate Action: Update the Linux kernel to version 6.18.52, 7.2.6, or 7.3-rc1 and later, where the mutex locking logic has been corrected.
Proactive Monitoring: Monitor system logs for kernel-level errors or unexpected driver resets that may indicate an attempt to exploit race conditions in the wireless stack.
Compensating Controls: Restrict access to the wireless management interface to trusted devices and ensure that wireless segments are isolated from critical internal network infrastructure.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this kernel vulnerability necessitates immediate attention for all systems utilizing the mt7996 wireless chipset. Administrators should prioritize patching the kernel to the identified fixed versions to eliminate the race condition and prevent potential exploitation of the wireless subsystem.
More Linux CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section