{"api_version":"1","generated_at":"2026-10-03T21:14:15+00:00","cve":"CVE-2026-90379","urls":{"html":"https://cve.report/CVE-2026-90379","api":"https://cve.report/api/cve/CVE-2026-90379.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90379","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90379"},"summary":{"title":"wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash\n\nWhen an AER error occurs and the bus is hung, the register reads return\n0xFFFFFFFF, causing the DMA queue state to be corrupted and resulting in\nan invalid memory access when accessing q->desc[] or q->entry[].\n\nUnable to handle kernel paging request at virtual address\nffffffc01099eac0\npc : mt76_dma_add_buf+0x124/0x188 [mt76]\nlr : mt76_dma_rx_fill+0x11c/0x1d8 [mt76]\nsp : ffffffc016d9bbf0\nx29: ffffffc016d9bc10 x28: 0000000000000000\nx27: 0000000000000000 x26: ffffffb7855e50b8\nx25: ffffffb80d04f000 x24: 0000000000000000\nx23: 0000000000000ec0 x22: ffffffb796803648\nx21: ffffffb796801f80 x20: ffffffb7968035f8\nx19: 0000000000000ec0 x18: 0000000000000000\nx17: 000000004ec00000 x16: 000000000ec00000\nx15: ffffffc01099eac0 x14: 000000004ec00000\nx13: 00000000ffc5a000 x12: ffffffc016d9bc32\nx11: 00000000ffffffff x10: 0000000000000002\nx9 : 0000000000000000 x8 : 000000000000b4ac\nx7 : 0000000000000a20 x6 : ffffffb6c1806400\nx5 : 0000000000000000 x4 : ffffffb80d04f000\nx3 : 0000000000000000 x2 : 0000000000000001\nx1 : 000000000ec04000 x0 : ffffffb7968035f8\nCall trace:\n mt76_dma_add_buf+0x124/0x188 [mt76 (HASH:1029 4)]\n mt76_dma_rx_reset+0xe8/0xfc [mt76 (HASH:1029 4)]\n mt7921_wpdma_reset+0x188/0x1b0 [mt7921e (HASH:ee48 5)]\n mt7921e_mac_reset+0x128/0x418 [mt7921e (HASH:ee48 5)]\n mt7921_mac_reset_work+0xac/0x1a8 [mt7921_common (HASH:f721 6)]\n process_one_work+0x188/0x514\n worker_thread+0x12c/0x300\n kthread+0x140/0x1fc\n ret_from_fork+0x10/0x30\n\nFix the invalid memory access by validating the DMA index read from the\nhardware before it is used as a queue index. An out-of-range value, such\nas the 0xFFFFFFFF returned while the bus is hung, is now clamped so it can\nno longer corrupt q->head or q->tail. In addition, check the bus_hung flag\nin mt7921_mac_reset_work() before attempting the reset sequence, reject MCU\nmessages while the bus is hung, and install no-op bus operations when an\nunrecoverable AER error is detected, preventing further invalid hardware\naccesses.\n\nDue to hardware limitations - such as the lack of a connected hardware\nreset pin or the absence of host re-probe functionality - affected Wi-Fi\ndevices may not fully recover to a normal operational state after\ncertain errors, even with AER enabled.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:37","updated_at":"2026-09-18 18:17:55"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/670b3dc4e3713542a9f002d38fb9d1740b9e342b","name":"https://git.kernel.org/stable/c/670b3dc4e3713542a9f002d38fb9d1740b9e342b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/915672c5ae32deeb72f4572856d123f314791136","name":"https://git.kernel.org/stable/c/915672c5ae32deeb72f4572856d123f314791136","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f544bcba4721e1074e9bc6666f0ef4f8b96ddba8","name":"https://git.kernel.org/stable/c/f544bcba4721e1074e9bc6666f0ef4f8b96ddba8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90379","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90379","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 17f1de56df051229988aab37e01971c9713c4a31 670b3dc4e3713542a9f002d38fb9d1740b9e342b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 17f1de56df051229988aab37e01971c9713c4a31 f544bcba4721e1074e9bc6666f0ef4f8b96ddba8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 17f1de56df051229988aab37e01971c9713c4a31 915672c5ae32deeb72f4572856d123f314791136 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90379","cve":"CVE-2026-90379","epss":"0.002390000","percentile":"0.152150000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/wireless/mediatek/mt76/dma.c","drivers/net/wireless/mediatek/mt76/mcu.c","drivers/net/wireless/mediatek/mt76/mt76_connac.h","drivers/net/wireless/mediatek/mt76/mt7921/mac.c","drivers/net/wireless/mediatek/mt76/mt7921/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"670b3dc4e3713542a9f002d38fb9d1740b9e342b","status":"affected","version":"17f1de56df051229988aab37e01971c9713c4a31","versionType":"git"},{"lessThan":"f544bcba4721e1074e9bc6666f0ef4f8b96ddba8","status":"affected","version":"17f1de56df051229988aab37e01971c9713c4a31","versionType":"git"},{"lessThan":"915672c5ae32deeb72f4572856d123f314791136","status":"affected","version":"17f1de56df051229988aab37e01971c9713c4a31","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/wireless/mediatek/mt76/dma.c","drivers/net/wireless/mediatek/mt76/mcu.c","drivers/net/wireless/mediatek/mt76/mt76_connac.h","drivers/net/wireless/mediatek/mt76/mt7921/mac.c","drivers/net/wireless/mediatek/mt76/mt7921/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.16"},{"lessThan":"4.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"4.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"4.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash\n\nWhen an AER error occurs and the bus is hung, the register reads return\n0xFFFFFFFF, causing the DMA queue state to be corrupted and resulting in\nan invalid memory access when accessing q->desc[] or q->entry[].\n\nUnable to handle kernel paging request at virtual address\nffffffc01099eac0\npc : mt76_dma_add_buf+0x124/0x188 [mt76]\nlr : mt76_dma_rx_fill+0x11c/0x1d8 [mt76]\nsp : ffffffc016d9bbf0\nx29: ffffffc016d9bc10 x28: 0000000000000000\nx27: 0000000000000000 x26: ffffffb7855e50b8\nx25: ffffffb80d04f000 x24: 0000000000000000\nx23: 0000000000000ec0 x22: ffffffb796803648\nx21: ffffffb796801f80 x20: ffffffb7968035f8\nx19: 0000000000000ec0 x18: 0000000000000000\nx17: 000000004ec00000 x16: 000000000ec00000\nx15: ffffffc01099eac0 x14: 000000004ec00000\nx13: 00000000ffc5a000 x12: ffffffc016d9bc32\nx11: 00000000ffffffff x10: 0000000000000002\nx9 : 0000000000000000 x8 : 000000000000b4ac\nx7 : 0000000000000a20 x6 : ffffffb6c1806400\nx5 : 0000000000000000 x4 : ffffffb80d04f000\nx3 : 0000000000000000 x2 : 0000000000000001\nx1 : 000000000ec04000 x0 : ffffffb7968035f8\nCall trace:\n mt76_dma_add_buf+0x124/0x188 [mt76 (HASH:1029 4)]\n mt76_dma_rx_reset+0xe8/0xfc [mt76 (HASH:1029 4)]\n mt7921_wpdma_reset+0x188/0x1b0 [mt7921e (HASH:ee48 5)]\n mt7921e_mac_reset+0x128/0x418 [mt7921e (HASH:ee48 5)]\n mt7921_mac_reset_work+0xac/0x1a8 [mt7921_common (HASH:f721 6)]\n process_one_work+0x188/0x514\n worker_thread+0x12c/0x300\n kthread+0x140/0x1fc\n ret_from_fork+0x10/0x30\n\nFix the invalid memory access by validating the DMA index read from the\nhardware before it is used as a queue index. An out-of-range value, such\nas the 0xFFFFFFFF returned while the bus is hung, is now clamped so it can\nno longer corrupt q->head or q->tail. In addition, check the bus_hung flag\nin mt7921_mac_reset_work() before attempting the reset sequence, reject MCU\nmessages while the bus is hung, and install no-op bus operations when an\nunrecoverable AER error is detected, preventing further invalid hardware\naccesses.\n\nDue to hardware limitations - such as the lack of a connected hardware\nreset pin or the absence of host re-probe functionality - affected Wi-Fi\ndevices may not fully recover to a normal operational state after\ncertain errors, even with AER enabled."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:A - mt76_dma_sync_idx() sets q->head from Q_READ(q, dma_idx) (readl of the mt7921 PCIe DMA ring). A hung endpoint returns 0xFFFFFFFF, truncated to u16 0xFFFF. That register is the wireless DMA engine index; PCIe AER/completion-timeout on this WiFi adapter is an adjacent-radio event, not a parsed routable packet, so the vector is Adjacent.\nAC:L - Once dma_idx reads 0xFFFFFFFF, mt76_dma_sync_idx() stores 0xFFFF in q->head with no bounds check, and mt76_dma_rx_reset() then calls mt76_dma_rx_fill() which indexes q->desc[]/q->entry[] at that value. MCU timeout in mt7921_mcu_parse_response() queues mt792x_reset() automatically when the hung device stops completing commands; no race is required.\nPR:N - mt7921_mcu_parse_response() queues reset on MCU timeout and mt7921_mac_reset_work() runs mt7921e_mac_reset() with no capability, credential, or association check. An adjacent attacker who hangs the mt7921 endpoint needs no host account; the 0600 chip_reset debugfs file is not on this path.\nUI:N - mt7921_mac_reset_work() is scheduled onto the mt76 workqueue by mt792x_reset() after an MCU timeout; the OOB then occurs in kernel context during mt76_dma_rx_reset(). No victim mount, file open, or other interactive action is required beyond the interface being up.\nS:U - The out-of-bounds stores in mt76_dma_add_buf()/mt76_dma_add_rx_buf() target host kernel q->desc[] and q->entry[] allocated by dmam_alloc_coherent/devm_kzalloc. This stays inside the kernel's own authority and does not bypass a VM, IOMMU, or sandbox boundary.\nC:H - q->head is a u16 loaded from the hung-bus dma_idx (0xFFFF) while MT7921_RX_RING_SIZE is 1536, so mt76_dma_add_rx_buf() reads q->entry[0xFFFF] and q->desc[0xFFFF] far past the allocated arrays. That out-of-bounds access of kernel DMA-descriptor and queue-entry memory is High confidentiality per OOB guidance.\nI:H - mt76_dma_add_buf() WRITE_ONCE-stores buf0/buf1/ctrl/info into q->desc[0xFFFF] and writes dma_addr/len into q->entry[0xFFFF], then leaves q->tail at 0xFFFF so later dequeue continues the same out-of-bounds writes. An out-of-bounds write of kernel DMA state is High integrity.\nA:H - The in-tree crash is a kernel paging request at mt76_dma_add_buf() called from mt76_dma_rx_fill() during mt76_dma_rx_reset() on the mt7921e_mac_reset <- mt7921_mac_reset_work path, which oopses/panics the host (High availability)."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:54:55.903Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/670b3dc4e3713542a9f002d38fb9d1740b9e342b"},{"url":"https://git.kernel.org/stable/c/f544bcba4721e1074e9bc6666f0ef4f8b96ddba8"},{"url":"https://git.kernel.org/stable/c/915672c5ae32deeb72f4572856d123f314791136"}],"title":"wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90379","datePublished":"2026-09-17T16:09:17.297Z","dateReserved":"2026-09-11T19:38:34.809Z","dateUpdated":"2026-09-18T17:54:55.903Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:37","lastModifiedDate":"2026-09-18 18:17:55","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90379","Ordinal":"1","Title":"wifi: mt76: mt7921: Add PCIe AER handler support to prevent syst","CVE":"CVE-2026-90379","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90379","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash\n\nWhen an AER error occurs and the bus is hung, the register reads return\n0xFFFFFFFF, causing the DMA queue state to be corrupted and resulting in\nan invalid memory access when accessing q->desc[] or q->entry[].\n\nUnable to handle kernel paging request at virtual address\nffffffc01099eac0\npc : mt76_dma_add_buf+0x124/0x188 [mt76]\nlr : mt76_dma_rx_fill+0x11c/0x1d8 [mt76]\nsp : ffffffc016d9bbf0\nx29: ffffffc016d9bc10 x28: 0000000000000000\nx27: 0000000000000000 x26: ffffffb7855e50b8\nx25: ffffffb80d04f000 x24: 0000000000000000\nx23: 0000000000000ec0 x22: ffffffb796803648\nx21: ffffffb796801f80 x20: ffffffb7968035f8\nx19: 0000000000000ec0 x18: 0000000000000000\nx17: 000000004ec00000 x16: 000000000ec00000\nx15: ffffffc01099eac0 x14: 000000004ec00000\nx13: 00000000ffc5a000 x12: ffffffc016d9bc32\nx11: 00000000ffffffff x10: 0000000000000002\nx9 : 0000000000000000 x8 : 000000000000b4ac\nx7 : 0000000000000a20 x6 : ffffffb6c1806400\nx5 : 0000000000000000 x4 : ffffffb80d04f000\nx3 : 0000000000000000 x2 : 0000000000000001\nx1 : 000000000ec04000 x0 : ffffffb7968035f8\nCall trace:\n mt76_dma_add_buf+0x124/0x188 [mt76 (HASH:1029 4)]\n mt76_dma_rx_reset+0xe8/0xfc [mt76 (HASH:1029 4)]\n mt7921_wpdma_reset+0x188/0x1b0 [mt7921e (HASH:ee48 5)]\n mt7921e_mac_reset+0x128/0x418 [mt7921e (HASH:ee48 5)]\n mt7921_mac_reset_work+0xac/0x1a8 [mt7921_common (HASH:f721 6)]\n process_one_work+0x188/0x514\n worker_thread+0x12c/0x300\n kthread+0x140/0x1fc\n ret_from_fork+0x10/0x30\n\nFix the invalid memory access by validating the DMA index read from the\nhardware before it is used as a queue index. An out-of-range value, such\nas the 0xFFFFFFFF returned while the bus is hung, is now clamped so it can\nno longer corrupt q->head or q->tail. In addition, check the bus_hung flag\nin mt7921_mac_reset_work() before attempting the reset sequence, reject MCU\nmessages while the bus is hung, and install no-op bus operations when an\nunrecoverable AER error is detected, preventing further invalid hardware\naccesses.\n\nDue to hardware limitations - such as the lack of a connected hardware\nreset pin or the absence of host re-probe functionality - affected Wi-Fi\ndevices may not fully recover to a normal operational state after\ncertain errors, even with AER enabled.","Type":"Description","Title":"wifi: mt76: mt7921: Add PCIe AER handler support to prevent syst"}]}}}