wifi: mt76: mt7915: fix double hif2 init on the non-WED path
Summary
| CVE | CVE-2026-90354 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:34 UTC |
| Updated | 2026-09-17 17:17:34 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: fix double hif2 init on the non-WED path
mt7915_pci_init_hif2() was called unconditionally and again inside the
WED-inactive branch. The helper increments the global hif_idx, writes the
PCIe RECOG_ID register and takes a get_device() reference via
mt7915_pci_get_hif2(), while removal only drops one reference. On non-WED
dual-hif hardware this double-incremented hif_idx, wrote RECOG_ID twice and
leaked a device reference. Only the call inside the WED-inactive branch is
correct; drop the unconditional one. hif2 is already initialised to NULL. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 eac18fadc791928379b179e54636494b92f8cf86 git |
Not specified |
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 927fe8c0eb8c10295bc0018c8faa4d91f8fe98c6 git |
Not specified |
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 bd2e8f535ae35beb45a7fcc17ec9bbf8dc4db5fe git |
Not specified |
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 249cbaa1873550689fab136b74982cbba74c4169 git |
Not specified |
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 29fbc5256c2d8448f084ff179d2e5092ecd1fc54 git |
Not specified |
| CNA |
Linux |
Linux |
affected cacdd67812c6df824704ac078f1770188a485ff9 3ae8ad277e2819a281b0e36b55633c8515c16ce7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/29fbc5256c2d8448f084ff179d2e5092ecd1fc54 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/927fe8c0eb8c10295bc0018c8faa4d91f8fe98c6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3ae8ad277e2819a281b0e36b55633c8515c16ce7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/249cbaa1873550689fab136b74982cbba74c4169 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/eac18fadc791928379b179e54636494b92f8cf86 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/bd2e8f535ae35beb45a7fcc17ec9bbf8dc4db5fe |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.