CVE-2026-90379

8.8

Linux · Kernel

A PCIe AER handler flaw in the Linux kernel mt76 driver causes memory corruption and system crashes when bus errors occur, potentially allowing for system-wide instability.

Executive summary

An unauthenticated memory corruption vulnerability in the Linux kernel mt76 driver allows for system crashes and potential denial of service via PCIe AER errors.

Vulnerability

This vulnerability is a memory safety issue occurring within the mt76 driver for mt7921 Wi-Fi hardware. When a PCIe Advanced Error Reporting (AER) error triggers a bus hang, the driver incorrectly handles returned register values, leading to corrupted DMA queue pointers and subsequent invalid memory access.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its high impact on system availability. Successful exploitation of this flaw leads to a kernel panic, resulting in immediate system downtime. In business-critical environments, such as servers or network appliances relying on this hardware, this represents a significant risk of service interruption and potential data loss associated with sudden system crashes.

Remediation

Immediate Action: Update the Linux kernel to version 6.18.52, 7.2.6, or later releases where the PCIe AER handler fix is implemented.

Proactive Monitoring: Monitor system logs for PCIe error messages or AER-related warnings that may precede a driver-induced crash.

Compensating Controls: If patching is delayed, restrict physical or network access to the affected hardware components to minimize the probability of triggering bus errors that could lead to exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system failure and the high CVSS severity, administrators should prioritize kernel updates as part of the next maintenance cycle. Applying the documented fixes is the only reliable way to ensure the mt76 driver correctly manages PCIe bus errors and prevents the resulting memory corruption.

More Linux CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources