wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length

Summary

CVECVE-2026-90382
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:17:37 UTC
Updated2026-09-17 17:17:37 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length The MPDU length in the rx descriptor comes from the hardware. In monitor mode with the fcsfail filter enabled, the hardware passes up corrupted frames, and a corrupted frame can report a length larger than the received buffer. The bounds check correctly discards such frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage frame taints the kernel, and panics it on the first such frame when panic_on_warn is set. Drop the WARN and discard the frame silently, matching what commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx status and rx path") did for the neighboring rx and tx status paths. Observed immediately on rx with an MT7612U in fcsfail monitor mode on a busy channel.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa 61b1f6d92249bc34580ff19de7c69c805f82adca git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa c65bbfc730df9ebf0fea8e286b0ad2dfab03dbfe git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa d55e7aede542c4c76ead82d37d0c112f21eb2ac2 git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa b6e7958602bd1acdb8ae92703b6689a28bcc9bc0 git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa 2d31e332c13b1db7745a7bd9cf74bc105524bcac git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa 17d6b89e09eac2d90272fceeba3644e92212e02f git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa 6def491fe9c4e83aa8cba62d74e9d4ab751ee967 git Not specified
CNA Linux Linux affected 7bc04215a66b60e198aecaee8418f6d79fa19faa 81497634d9f872fd3e8b03aada55574afff6f174 git Not specified
CNA Linux Linux affected 4.16 Not specified
CNA Linux Linux unaffected 4.16 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/17d6b89e09eac2d90272fceeba3644e92212e02f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6def491fe9c4e83aa8cba62d74e9d4ab751ee967 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/61b1f6d92249bc34580ff19de7c69c805f82adca 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b6e7958602bd1acdb8ae92703b6689a28bcc9bc0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c65bbfc730df9ebf0fea8e286b0ad2dfab03dbfe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2d31e332c13b1db7745a7bd9cf74bc105524bcac 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/81497634d9f872fd3e8b03aada55574afff6f174 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d55e7aede542c4c76ead82d37d0c112f21eb2ac2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report