CVE-2026-90366 PUBLISHED

wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV

When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a near-maximum beacon template the extra 8 bytes could push the offload command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic(). Reserve room for both countdown TLVs.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 98686cd21624c75a043e96812beadddf4f6f48e5 to 1d348f96623ec20d700af7d4dfc00a74da6238ac (excl.)
  • affected from 98686cd21624c75a043e96812beadddf4f6f48e5 to bc1d694a1ffe0062c3adf0db1d64ad54454398ec (excl.)
  • affected from 98686cd21624c75a043e96812beadddf4f6f48e5 to 45d8896e4cffffb2c6554ccbec6efe7a0d53166f (excl.)
  • affected from 98686cd21624c75a043e96812beadddf4f6f48e5 to 1a51aff0e048dc5b8252d65808b79939c942d6ec (excl.)
  • affected from 98686cd21624c75a043e96812beadddf4f6f48e5 to 50c66bab321140c49aa2ed779a3ec9d2f085b458 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.2 is affected
  • unaffected from 0 to 6.2 (excl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References