CVE-2026-90381

8.8

Linux · Kernel

A logic error in the Linux kernel mt76 WiFi driver causes improper handling of channel contexts during rapid channel switching, potentially leading to memory corruption or system instability.

Executive summary

A critical vulnerability in the Linux kernel mt76 WiFi driver allows unauthenticated attackers on an adjacent network to potentially achieve system impact due to improper channel context handling.

Vulnerability

This vulnerability is a logic flaw within the mt76 WiFi driver, specifically in the mt76_switch_vif_chanctx function. The issue arises when performing channel switches on different radios within a short timeframe, allowing an unauthenticated attacker on an adjacent network to trigger an unstable state.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for high impact on system integrity, confidentiality, and availability. Successful exploitation could lead to kernel-level crashes, denial of service, or potentially arbitrary code execution within the kernel context, posing significant risks to system stability and data security.

Remediation

Immediate Action: Update the Linux kernel to version 7.2.6 or later, or apply the upstream commits referenced in the kernel stable repository.

Proactive Monitoring: Monitor system logs for kernel panics or driver-related errors, particularly if the environment relies heavily on MT76-based wireless hardware.

Compensating Controls: Restrict access to wireless networks to trusted devices and ensure that wireless infrastructure is isolated from critical internal segments where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity and the potential for kernel-level impact, administrators should prioritize patching affected Linux distributions. Organizations utilizing devices with MT76 wireless chipsets should verify their kernel version and apply the necessary updates to eliminate this risk.

More Linux CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources