CVE-2026-90371
8.8Linux · Kernel
A race condition in the Linux kernel mt76 wifi driver during RXDMAD_C buffer recycling allows for potential memory corruption or system instability.
Executive summary
A race condition vulnerability in the Linux kernel mt76 Wi-Fi driver could allow an adjacent attacker to trigger memory corruption and potentially achieve system compromise.
Vulnerability
The vulnerability is a race condition (CWE-362) within the mt76 driver where RXDMAD_C buffers are incorrectly recycled while bound to a different NAPI context. This allows an unauthenticated, adjacent attacker to trigger a race against the owning NAPI process, leading to undefined behavior.
Business impact
The flaw carries a CVSS score of 8.8, indicating high severity due to the potential for full system compromise. Successful exploitation could lead to unauthorized code execution or denial of service, impacting the availability and integrity of systems relying on affected MediaTek wireless hardware.
Remediation
Immediate Action: Update the Linux kernel to version 6.18.52, 7.2.6, or 7.3-rc1 or later to implement the corrected buffer recycling logic.
Proactive Monitoring: Monitor system logs for kernel panics or driver-related errors that may indicate failed exploitation attempts or memory instability.
Compensating Controls: Restrict access to wireless networks utilizing the affected hardware to trusted devices, reducing the probability of an attacker reaching the vulnerable adjacent network interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS severity, organizations utilizing Linux systems with MediaTek wireless hardware should prioritize kernel updates. Applying the provided stable release patches is essential to prevent potential memory corruption and maintain system stability.
More Linux CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section