{"id":"CVE-2026-90380","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete\n\nA use-after-free issue occurs in mt76_rx_poll_complete due to a race\ncondition","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete\n\nA use-after-free issue occurs in mt76_rx_poll_complete due to a race\ncondition. The STA has already bee…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= c948b5da6bbec742b433138e3e3f9537a85af2e5 < aaf414bf81ab4b680580871784b0b929818188eb","Linux >= c948b5da6bbec742b433138e3e3f9537a85af2e5 < b250943f3f8351385a17972bda001664a5c51008","Linux >= c948b5da6bbec742b433138e3e3f9537a85af2e5 < 217f9e7bb02558759be9d9ecfe532e9708741c50","Linux 6.7"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:56.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90380","references":[{"url":"https://git.kernel.org/stable/c/217f9e7bb02558759be9d9ecfe532e9708741c50","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaf414bf81ab4b680580871784b0b929818188eb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b250943f3f8351385a17972bda001664a5c51008","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00309,"epssPercentile":0.23937,"ingestedAt":"2026-09-17T16:21:47.806Z","slug":"CVE-2026-90380","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete\n\nA use-after-free issue occurs in mt76_rx_poll_complete due to a race\ncondition. The STA has already been removed, but the rx_status still\nhad a pointer to the wcid in the STA.\n\nSet the links' wcid pointers to be NULL for a MLD in\nmt7925_sta_pre_rcu_remove()\n\nBUG: KASAN: invalid-access in mt76_rx_poll_complete+0x280/0x470\nCall trace:\ndump_backtrace+0xec/0x128\nshow_stack+0x18/0x28\ndump_stack_lvl+0x40/0xc8\nprint_report+0x1b8/0x710\nkasan_report+0xe0/0x144\ndo_bad_area+0x120/0x260\ndo_tag_check_fault+0x20/0x34\ndo_mem_abort+0x54/0xa8\nel1_abort+0x3c/0x5c\nel1h_64_sync_handler+0x40/0xcc\nel1h_64_sync+0x7c/0x80\nmt76_rx_poll_complete+0x280/0x470\nmt76_dma_rx_poll+0x114/0x51c\nmt792x_poll_rx+0x60/0xf8\nnapi_threaded_poll_loop+0xe0/0x450\nnapi_threaded_poll+0x80/0x9c\nkthread+0x11c/0x158\nret_from_fork+0x10/0x20\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":207285,"id":"CVE-2026-90380","ts":1789757340420,"field":"cvss","old":null,"new":"8.8"},{"seq":207284,"id":"CVE-2026-90380","ts":1789757340420,"field":"severity","old":"none","new":"high"}]}