{"id":"CVE-2026-90351","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed\n\nIf the WED attach for the primary PCIe function fails, the probe path\nstill attached wed_hif…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed\n\nIf the WED attach for the primary PCIe function fails, the probe path\nstill attached wed_hif…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 83eafc9251d6d30574b629ac637c56d168fcbdd9 < 76144da3c6184c7850631ad79d0600ac8bf7649a","Linux >= 83eafc9251d6d30574b629ac637c56d168fcbdd9 < d566387df8306257d2f703a0d99fd9896400317e","Linux >= 83eafc9251d6d30574b629ac637c56d168fcbdd9 < 7c1924332e986019c6bcddf55c843361cccac73f","Linux 6.8"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:33.913","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90351","references":[{"url":"https://git.kernel.org/stable/c/76144da3c6184c7850631ad79d0600ac8bf7649a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c1924332e986019c6bcddf55c843361cccac73f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d566387df8306257d2f703a0d99fd9896400317e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.815Z","epss":0.00198,"epssPercentile":0.09839,"slug":"CVE-2026-90351","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed\n\nIf the WED attach for the primary PCIe function fails, the probe path\nstill attached wed_hif2 for the secondary function, leaving the device\nin an inconsistent half-WED configuration that crashes later. The hif2\ncall also re-enabled hwrro_mode, which the failed primary attach had\njust turned off.\n\nSkip the hif2 WED setup when the primary WED device is not active.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}