wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
Summary
| CVE | CVE-2026-90373 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:36 UTC |
| Updated | 2026-09-17 17:17:36 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
mt7915_remove_interface() cleared the wcid mask bit with no lock held and
before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared
with the allocators, which all run under dev->mt76.mutex; on DBDC the two
wiphys share one mt76_dev, so this raced add_interface/sta_add on the
other band and could leak or double-hand-out a wcid. Clearing the bit
before the RCU pointer also let a concurrent allocation reuse the index
and publish its wcid, which the subsequent NULL assignment then wiped.
Move the clear into the existing mutex section, after the RCU pointer is
cleared. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected f3049b88b2b32326df97461813ae73e8bbc296fc 5dce25f1d609ba991a9c22c27be586c92f03ed77 git |
Not specified |
| CNA |
Linux |
Linux |
affected f3049b88b2b32326df97461813ae73e8bbc296fc b4a41a47a67c788e6b0625fa517ec8872e99bb6c git |
Not specified |
| CNA |
Linux |
Linux |
affected f3049b88b2b32326df97461813ae73e8bbc296fc a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b git |
Not specified |
| CNA |
Linux |
Linux |
affected f3049b88b2b32326df97461813ae73e8bbc296fc 6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/a97b2b942d2f8f12fbd6a7caafc735d1ad115e6b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5dce25f1d609ba991a9c22c27be586c92f03ed77 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b4a41a47a67c788e6b0625fa517ec8872e99bb6c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.